CVE-2020-11652
SaltStack Salt Path Traversal Vulnerability
Summary
SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
Affected software
Vendor: SaltStack · Product: Salt
Weakness types (CWE):
What to do
This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.
Related vulnerabilities in SaltStack
| CVE | Name | EPSS | Exploited |
|---|---|---|---|
| CVE-2020-16846 | SaltStack Salt Shell Injection Vulnerability | 99.6% | Yes |
| CVE-2020-11651 | SaltStack Salt Authentication Bypass Vulnerability | 96.4% | Yes |
Is your domain exposed?
Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.
Get your free reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.