CyberSec.Space Logo
Back to CVE Browser

CVE-2020-11652

Known Exploited (CISA KEV)MEDIUM
6.5
CVSS Severity Score
EPSS Score59.6630%
EPSS Percentile86.15th
PublishedApr 30, 2020
Last ModifiedNov 7, 2025

Vulnerability Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Affected Platforms (CPE)

πŸ“¦
Saltstack

Salt

< 2019.2.4
πŸ“¦
Saltstack

Salt

>= 3000 and < 3000.2
πŸ’»
Opensuse

Leap

= 15.1
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Debian

Debian Linux

= 10.0
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ’»
Canonical

Ubuntu Linux

= 18.04
πŸ“¦
Blackberry

Workspaces Server

<= 7.1.3
πŸ“¦
Blackberry

Workspaces Server

>= 8.0.0 and <= 8.2.6
πŸ“¦
Blackberry

Workspaces Server

= 9.1.0
πŸ“¦
Vmware

Application Remote Collector

= 7.5.0
πŸ“¦
Vmware

Application Remote Collector

= 8.0.0

References & Advisories

Related Vulnerabilities