Skip to content
COOEY

EXPOSURES › CVE-2020-11652

CVE-2020-11652

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-11652 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

SaltStack Salt's ClearFuncs path traversal flaw lets authenticated users read arbitrary files, exposing sensitive data if unpatched.

The SaltStack Salt master process ClearFuncs component contains a path traversal vulnerability allowing authenticated users to access files outside their intended directory. DIB organizations must patch this unpatched CVE immediately, as it enables data exfiltration and violates CMMC/NIST 800-171 data protection requirements. While not an RCE or zero-day, the fact it is in CISA's KEV list proves it was actively exploited in the wild.

Shame score — A known path traversal flaw in a widely used infrastructure tool that was actively exploited in the wild (KEV) and required patching, representing a negligent failure to maintain secure software.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

SENTIMENT · TRUSTED SOURCES
synthesis neutral -0.20
Vulnerability disclosed with standard mitigation guidance; no severe fallout or praise.
cooey ↗ neutral -0.20
Neutral disclosure with standard mitigation guidance.
"SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.