FlawAtlas
Search the atlas
CVE-2020-11652 Moderate

Confirmed as exploited

CVE-2020-11652

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Exploit probability 86.2%
Published April 30, 2020
Required by May 3, 2022
Last source change June 10, 2026

01 / ACTION

Required action

Apply updates per vendor instructions.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

46 explicit affected versions

PyPI salt

160 explicit affected versions

PyPI salt

160 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2020-11652

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

View original source
Open Source Vulnerabilities CVE-2020-11652

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

View original source
Open Source Vulnerabilities PYSEC-2020-103

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

View original source
Open Source Vulnerabilities GHSA-vp49-2g4r-m3x3

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

View original source

05 / REFERENCES

Further evidence