EXPOSURES › CVE-2020-11652
CVE-2020-11652
HIGH ⌖ ON CISA KEV · EXPLOITEDSaltStack Salt's ClearFuncs path traversal flaw lets authenticated users read arbitrary files, exposing sensitive data if unpatched.
The SaltStack Salt master process ClearFuncs component contains a path traversal vulnerability allowing authenticated users to access files outside their intended directory. DIB organizations must patch this unpatched CVE immediately, as it enables data exfiltration and violates CMMC/NIST 800-171 data protection requirements. While not an RCE or zero-day, the fact it is in CISA's KEV list proves it was actively exploited in the wild.
Shame score — A known path traversal flaw in a widely used infrastructure tool that was actively exploited in the wild (KEV) and required patching, representing a negligent failure to maintain secure software.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
"SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability."