Umbra Wiki cve cve/CVE-2020-11652
Back to wiki

CVE-2020-11652 — SaltStack Salt Path Traversal Vulnerability

provenance: imported · CVE: CVE-2020-11652

CVE-2020-11652: SaltStack Salt Path Traversal Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project SaltStack
Product Salt
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Unknown

Description

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-11652

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-11652
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog