CVE-2020-11651

saltstack/salt
on github

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*3000 (including)3000.2*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*n/a2019.2.4*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*n/an/a15.1
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*n/an/a8.0
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*n/an/a18.04
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*n/an/a16.04
cpe:2.3:a:vmware:application_remote_collector:8.0.0:*:*:*:*:*:*:*n/an/a8.0.0
cpe:2.3:a:vmware:application_remote_collector:7.5.0:*:*:*:*:*:*:*n/an/a7.5.0

External Links