Umbra Wiki cve cve/CVE-2020-11652
Back to wiki

CVE-2020-11652 — SaltStack Salt Path Traversal Vulnerability

provenance: imported · CVE: CVE-2020-11652 · CWE: CWE-22

CVE-2020-11652: SaltStack Salt Path Traversal Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project SaltStack
Product Salt
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Unknown

Description

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-11652

Weakness behind it

CISA records this vulnerability as an instance of CWE-22. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-11652
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →