FAIL › dossier
Salt
PRODUCT· dossier confidence 50%
SaltStack's core automation platform suffered multiple high-severity remote code execution and path traversal flaws in 2020, allowing unauthenticated attackers to execute arbitrary commands and access sensitive data. These vulnerabilities highlight critical gaps in input validation and access control within the product's API and authentication layers.
PROFILE
CategoryConfiguration Management / AutomationWhat they doSaltStack provides Salt, an open-source configuration management and automation platform used for system administration and orchestration.
SECURITY POSTURE
The company has a history of critical remote code execution (RCE) and path traversal vulnerabilities in its core API and authentication mechanisms, indicating systemic issues in input validation and access control.
Notable failures
- CVE-2020-11651: Unauthenticated RCE via ClearFuncs
- CVE-2020-16846: Unauthenticated shell injection RCE
- CVE-2020-11652: Authenticated path traversal exposing sensitive files
Patterns: repeated unpatched edge-device RCEs; insufficient input validation in API endpoints; weak access control allowing unauthenticated command execution
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-11651 | high | SaltStack Salt's improperly validated ClearFuncs method calls allowed unauthenticated remote access to tokens and command execution on minions. |
| 2021-11-03 | CVE-2020-16846 | high | An unauthenticated attacker could execute arbitrary shell commands on Salt API servers via shell injection. |
| 2021-11-03 | CVE-2020-11652 | high | SaltStack Salt's ClearFuncs path traversal flaw lets authenticated users read arbitrary files, exposing sensitive data if unpatched. |
Open questions: Current patch status and remediation timeline for CVE-2020-11651, CVE-2020-16846, and CVE-2020-11652 · Whether SaltStack has implemented additional input validation or access control mechanisms post-2020 · Impact of these vulnerabilities on SaltStack's CMMC compliance posture for defense-industrial-base clients
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:48:08.943076+00:00