CVE-2020-11652

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
saltstacksalt
𝑥
< 2019.2.4
saltstacksalt
3000 ≤
𝑥
< 3000.2
opensuseleap
15.1
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
blackberryworkspaces_server
𝑥
≤ 7.1.3
blackberryworkspaces_server
8.0.0 ≤
𝑥
≤ 8.2.6
blackberryworkspaces_server
9.1.0
vmwareapplication_remote_collector
7.5.0
vmwareapplication_remote_collector
8.0.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
salt
noble
dne
mantic
dne
lunar
dne
kinetic
not-affected
jammy
not-affected
focal
dne
eoan
ignored
bionic
Fixed 2017.7.4+dfsg1-1ubuntu18.04.2
released
xenial
Fixed 2015.8.8+ds-1ubuntu0.1
released
trusty
Fixed 0.17.5+ds-1ubuntu0.1~esm2
released
References