CVE-2020-11652
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 6.5epss 86%
from disclosure to weapon4 days
Published on NVDApr 30
1st PoC+4d
metasploitApr 30
CISA KEV+552d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
13 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03
Apply updates per vendor instructions.
Versions
Affected
pip/salt < 2019.2.4; pip/salt >= 3000, < 3000.2
Fixed in
pip/salt 2019.2.4; pip/salt 3000.2
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/apublic PoCs found — 13
exploitdbwww.exploit-db.com/exploits/48421unverifiedgithubgithub.com/Al1ex/CVE-2020-11652★ 6githubgithub.com/limon768/CVE-2020-11652-POC★ 4githubgithub.com/fanjq99/CVE-2020-11652★ 0vulncheckvulncheck.com/xdb/11b5248fe04cunverifiedvulncheckvulncheck.com/xdb/a45373fdc023unverifiedvulncheckvulncheck.com/xdb/d28267b60453unverifiedvulncheckvulncheck.com/xdb/5840ac3783acunverifiedcve_referencepacketstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/cf1bedb2b8aaunverifiedcve_referencepacketstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/d7a39011635dunverifiedvulncheckvulncheck.com/xdb/d9b31f42dc98unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.htmlhttp://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.htmlhttps://docs.saltstack.com/en/latest/topics/releases/2019.2.4.htmlhttps://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rsthttps://lists.debian.org/debian-lts-announce/2020/05/msg00027.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AGhttp://support.blackberry.com/kb/articleDetail?articleNumber=000063758https://usn.ubuntu.com/4459-1/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11652https://www.debian.org/security/2020/dsa-4676