Home / Vulnerabilities / CVE-2020-11652
MEDIUM SEVERITY
CVE-2020-11652 SaltStack · Salt

SaltStack Salt Path Traversal Vulnerability

Technical Severity

CVSS v3.1 Metrics

MEDIUM
6.5 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation Likelihood

EPSS Prediction

94.27 %
Predictive Probability
Percentile Rank
99.9 th

Documented as more likely to be exploited than 99.9% of known CVEs.

Detection Date

Nov 03, 2021

Remediation Due

May 03, 2022

CISA Catalog Active

Threat Analysis

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence