Back to search
CVE-2020-11652
Published: Apr 30, 2020
Modified: Oct 21, 2025
PUBLISHED
Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
openSUSE-SU-2020:0564
vendor-advisory
x_refsource_SUSE
DSA-4676
vendor-advisory
x_refsource_DEBIAN
http://www.vmware.com/security/advisories/VMSA-2020-0009.html
x_refsource_CONFIRM
20200528 SaltStack FrameWork Vulnerabilities Affecting Cisco Products
vendor-advisory
x_refsource_CISCO
[debian-lts-announce] 20200530 [SECURITY] [DLA 2223-1] salt security update
mailing-list
x_refsource_MLIST
openSUSE-SU-2020:1074
vendor-advisory
x_refsource_SUSE
USN-4459-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now