CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-11652

Known Exploited (CISA KEV)MEDIUM
6.5
CVSS Severity Score
EPSS Score59.6630%
EPSS Percentile86.15th
Published2020年4月30日
Last Modified2025年11月7日

Vulnerability Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Affected Platforms (CPE)

📦
Saltstack

Salt

< 2019.2.4
📦
Saltstack

Salt

>= 3000 and < 3000.2
💻
Opensuse

Leap

= 15.1
💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0
💻
Debian

Debian Linux

= 10.0
💻
Canonical

Ubuntu Linux

= 16.04
💻
Canonical

Ubuntu Linux

= 18.04
📦
Blackberry

Workspaces Server

<= 7.1.3
📦
Blackberry

Workspaces Server

>= 8.0.0 and <= 8.2.6
📦
Blackberry

Workspaces Server

= 9.1.0
📦
Vmware

Application Remote Collector

= 7.5.0
📦
Vmware

Application Remote Collector

= 8.0.0

References & Advisories

関連する脆弱性情報