Skip to content
COOEY

FAIL › dossier

SaltStack

VENDOR

· dossier confidence 20%

SaltStack's core automation platform suffered multiple high-severity remote code execution and path traversal flaws in 2020, allowing unauthenticated attackers to execute arbitrary commands and access sensitive data. These vulnerabilities highlight critical gaps in input validation and access control within the product's API and authentication layers.

PROFILE
CategoryautomationWhat they doSaltStack provides an open-source automation platform for system configuration management and orchestration. Websitehttps://saltstack.com ↗
SECURITY POSTURE

The company has a history of critical remote code execution (RCE) and path traversal vulnerabilities in its core product, highlighting gaps in input validation and access control within the API and authentication layers.

Notable failures
  • CVE-2020-11651: unauthenticated RCE via ClearFuncs
  • CVE-2020-16846: unauthenticated shell injection RCE
  • CVE-2020-11652: authenticated path traversal for arbitrary file read
Patterns: repeated unpatched edge-device RCEs; insufficient input validation in API layers; weak access control in authentication mechanisms
Reputationneutral (-0.11) · 9 trusted sources CoverageCISA · cooey · cooey · cooey · www.arista.com · www.cvefind.com
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2020-11651 high SaltStack Salt's improperly validated ClearFuncs method calls allowed unauthenticated remote access to tokens and command execution on minions.
2021-11-03 CVE-2020-16846 high An unauthenticated attacker could execute arbitrary shell commands on Salt API servers via shell injection.
2021-11-03 CVE-2020-11652 high SaltStack Salt's ClearFuncs path traversal flaw lets authenticated users read arbitrary files, exposing sensitive data if unpatched.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Vulnerability allows unauthenticated shell injection via SSH, posing severe risk to any Salt API deployment.
synthesisneutral-0.20
Vulnerability disclosed with standard mitigation guidance; no severe fallout or praise.
synthesisneutral-0.20
Vulnerability disclosed; no direct press coverage or authority condemnation found in provided sources.
www.dell.com ↗neutral+0.00
No relevant content; Dell support page.
No relevant content; CVE database site.
www.arista.com ↗neutral+0.00
No relevant content; Arista advisories page.
No relevant content; Local news article.
www.strix.ai ↗neutral+0.00
No relevant content; CVE database site.
cooey ↗severe-fallout-0.60
Vulnerability allows unauthenticated shell injection via SSH, posing severe risk to any Salt API deployment.
"SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client."
cooey ↗neutral-0.20
Neutral disclosure with standard mitigation guidance.
"SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability."
cooey ↗neutral-0.20
Neutral disclosure; notes best practices mitigate risk.
"Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability."
CISA ↗neutral+0.00
No relevant content; generic CISA page.
Open questions: current patch status for CVE-2020-11651/16846/11652 · whether SaltStack has implemented a bug bounty program to improve vulnerability disclosure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:48:42.401406+00:00