CVE-2020-11652

EUVD-2020-0172
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
saltstacksalt
𝑥
< 2019.2.4
saltstacksalt
3000 ≤
𝑥
< 3000.2
opensuseleap
15.1
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
blackberryworkspaces_server
𝑥
≤ 7.1.3
blackberryworkspaces_server
8.0.0 ≤
𝑥
≤ 8.2.6
blackberryworkspaces_server
9.1.0
vmwareapplication_remote_collector
7.5.0
vmwareapplication_remote_collector
8.0.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
salt
bionic
Fixed 2017.7.4+dfsg1-1ubuntu18.04.2
released
eoan
ignored
focal
dne
jammy
not-affected
kinetic
not-affected
lunar
dne
mantic
dne
noble
dne
trusty
Fixed 0.17.5+ds-1ubuntu0.1~esm2
released
xenial
Fixed 2015.8.8+ds-1ubuntu0.1
released
References