CVE-2020-11652: SaltStack Salt Path Traversal Vulnerability
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Other sources
SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3000.2 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2019.2.4 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 2019.2.4 - Upgrade
Upgrade
SaltStack Saltto a version that resolves this vulnerability.Fixed in 3000.2
Event History
Frequently Asked Questions
What is CVE-2020-11652?
CVE-2020-11652 is a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users.
How does the SaltStack Salt Path Traversal Vulnerability affect users?
The vulnerability affects Salt users who have authenticated access to the salt-master process ClearFuncs.
What is the severity of CVE-2020-11652?
CVE-2020-11652 has a severity rating of medium with a severity value of 6.5.
Which software versions are affected by CVE-2020-11652?
SaltStack Salt versions up to 2019.2.4 and 3000.2 are affected, as well as specific versions of Ubuntu, Debian, openSUSE Leap, Canonical Ubuntu Linux, BlackBerry Workspaces Server, and VMware Application Remote Collector.
How can I fix the SaltStack Salt Path Traversal Vulnerability?
To fix the vulnerability, you should upgrade SaltStack Salt to version 2019.2.4 or higher, or apply the necessary patches for the affected software versions.