CVE-2020-11651: SaltStack Salt Authentication Bypass Vulnerability
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
Other sources
SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/saltto a version that resolves this vulnerability.Fixed in 3000.2+dfsg1-1Fixed in 2016.11.2+ds-1+deb9u4Fixed in 2018.3.4+dfsg1-6+deb10u1Fixed in 2016.11.2+ds-1+deb9u3 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3000.2 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2019.2.4 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 2019.2.4 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 3000.2 - Compensating control
Restrict network access to the salt-master process (and its auth-bypass vulnerable endpoints such as ClearFuncs) so only trusted/authorized clients can reach it.
Event History
Frequently Asked Questions
What is CVE-2020-11651?
CVE-2020-11651 is a vulnerability found in SaltStack Salt that allows for an authentication bypass.
What is the severity of CVE-2020-11651?
CVE-2020-11651 has a severity rating of 9.8, which is considered critical.
How does CVE-2020-11651 affect SaltStack Salt?
CVE-2020-11651 affects the salt-master process ClearFuncs in SaltStack Salt.
How can a remote user exploit CVE-2020-11651?
A remote user can exploit CVE-2020-11651 to access some methods without authentication, potentially retrieving user tokens.
Are there any remedies available for CVE-2020-11651?
Remedies for CVE-2020-11651 are available in the affected software, such as SaltStack Salt versions 3000.2+dfsg1-1 and 2016.11.2+ds-1+deb9u4.