CVE-2020-11652

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some...

Basic Information

CVE State
PUBLISHED
Reserved Date
April 08, 2020
Published Date
April 30, 2020
Last Updated
February 04, 2025
Vendor
n/a
Product
n/a
Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Tags
cisa metasploit_scanner

CVSS Scores

CVSS v3.1

6.5 - MEDIUM

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v2.0

4.0

Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

SSVC Information

Exploitation
active
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2021-11-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2020-05-22 07:56:32 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

saltstack_salt_unauth_rce

Type: metasploit • Created: Unknown

Metasploit module for CVE-2020-11652

limon768/CVE-2020-11652-POC

Type: github • Created: 2024-01-17 04:15:16 UTC • Stars: 4

This is a fix POC CVE-2020-11651 & CVE-2020-11651

Al1ex/CVE-2020-11652

Type: github • Created: 2020-12-25 02:58:35 UTC • Stars: 6

CVE-2020-11652 & CVE-2020-11651

fanjq99/CVE-2020-11652

Type: github • Created: 2020-05-22 07:56:32 UTC • Stars: 0

saltstack CVE-2020-11652

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Metasploit