Skip to content
COOEY

FAIL › dossier

Salt

PRODUCT

· dossier confidence 50%

SaltStack's core automation platform suffered multiple high-severity remote code execution and path traversal flaws in 2020, allowing unauthenticated attackers to execute arbitrary commands and access sensitive data. These vulnerabilities highlight critical gaps in input validation and access control within the product's API and authentication layers.

PROFILE
CategoryConfiguration Management / AutomationWhat they doSaltStack provides Salt, an open-source configuration management and automation platform used for system administration and orchestration.
SECURITY POSTURE

The company has a history of critical remote code execution (RCE) and path traversal vulnerabilities in its core API and authentication mechanisms, indicating systemic issues in input validation and access control.

Notable failures
  • CVE-2020-11651: Unauthenticated RCE via ClearFuncs
  • CVE-2020-16846: Unauthenticated shell injection RCE
  • CVE-2020-11652: Authenticated path traversal exposing sensitive files
Patterns: repeated unpatched edge-device RCEs; insufficient input validation in API endpoints; weak access control allowing unauthenticated command execution
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2020-11651 high SaltStack Salt's improperly validated ClearFuncs method calls allowed unauthenticated remote access to tokens and command execution on minions.
2021-11-03 CVE-2020-16846 high An unauthenticated attacker could execute arbitrary shell commands on Salt API servers via shell injection.
2021-11-03 CVE-2020-11652 high SaltStack Salt's ClearFuncs path traversal flaw lets authenticated users read arbitrary files, exposing sensitive data if unpatched.
Open questions: Current patch status and remediation timeline for CVE-2020-11651, CVE-2020-16846, and CVE-2020-11652 · Whether SaltStack has implemented additional input validation or access control mechanisms post-2020 · Impact of these vulnerabilities on SaltStack's CMMC compliance posture for defense-industrial-base clients
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:48:08.943076+00:00