Improper Authentication in Salt - CVE-2020-11651
Published: May 4, 2020 / Updated: December 19, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the salt-master process "ClearFuncs" class does not properly validate method calls. A remote non-authenticated attacker can bypass authentication process and gain access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minion as root.
Note: this vulnerability is being actively exploited in the wild.
Affected software
Arch Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Transactional Server
Opensuse
Cisco Virtual Internet Routing Lab Personal Edition
Cisco Modeling Labs Corporate Edition
VMware vRealize Operations Manager (vROps)
salt (Debian package)
salt (Alpine package)
salt-minion (Ubuntu package)
salt-master (Ubuntu package)
salt-common (Ubuntu package)
python2-distro
python3-distro
salt-api (Ubuntu package)
salt-standalone-formulas-configuration
salt-ssh
salt-syndic
salt-fish-completion
salt-cloud
salt-doc
salt-bash-completion
salt-zsh-completion
salt-api
salt
python3-salt
salt-minion
salt-proxy
salt-transactional-update
salt-master
Dell EMC VxRail Appliance
How to mitigate CVE-2020-11651
salt (Debian package) - addressed in versions 2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1
salt (Alpine package) - addressed in versions 2019.2.4-r0, 3000.2-r0
salt-minion (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-master (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-common (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
python2-distro - update to 1.5.0-3.5.1
python3-distro - update to 1.5.0-3.5.1
Dell EMC VxRail Appliance - update to 7.0.203
salt-api (Ubuntu package) - addressed in versions 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-standalone-formulas-configuration - update to 3002.2-37.1
salt-ssh - update to 3002.2-37.1
salt-syndic - update to 3002.2-37.1
salt-fish-completion - update to 3002.2-37.1
salt-cloud - update to 3002.2-37.1
salt-doc - update to 3002.2-37.1
salt-bash-completion - update to 3002.2-37.1
salt-zsh-completion - update to 3002.2-37.1
salt-api - update to 3002.2-37.1
salt - update to 3002.2-37.1
python3-salt - update to 3002.2-37.1
salt-minion - update to 3002.2-37.1
salt-proxy - update to 3002.2-37.1
salt-transactional-update - update to 3002.2-37.1
salt-master - update to 3002.2-37.1
Links to Public Exploits and PoC-codes
- Exploit #9448 - CVE-2020-11651-PoC (Repository that contains a CVE-2020-11651 Exploit updated to work with the latest versions of python.) (December 19, 2023)
- Exploit #7299 - cve-2020-11651 () (January 30, 2022)
- Exploit #4968 - CVE-2020-11652 (CVE-2020-11652 & CVE-2020-11651) (December 28, 2020)
- Exploit #4894 - salt-rce-scanner-CVE-2020-11651-CVE-2020-11652 (Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.) (December 2, 2020)
- Exploit #2955 - CVE-2020-11651 (PoC for CVE-2020-11651) (June 3, 2020)
- Exploit #2995 - CVE-2020-11652 (saltstack CVE-2020-11652 ) (June 3, 2020)
- Exploit #2982 - salt-security-backports (Salt security backports for CVE-2020-11651 & CVE-2020-11652) (June 3, 2020)
- Exploit #2963 - cve-2020-11651-exp-plus () (June 3, 2020)
- Exploit #2962 - CVE-2020-11651-CVE-2020-11652-EXP (CVE-2020-11651&&CVE-2020-11652 EXP) (June 3, 2020)
- Exploit #2956 - CVE-2020-11651 (CVE-2020-11651: Proof of Concept) (June 3, 2020)
- Exploit #2954 - CVE-2020-11651 (PoC for CVE-2020-11651) (June 3, 2020)
- Exploit #2952 - SaltStack-Exp (CVE-2020-11651&&CVE-2020-11652 EXP) (June 3, 2020)
- Exploit #2950 - SaltStack-Exp (CVE-2020-11651&&CVE-2020-11652 EXP) (June 3, 2020)
- Exploit #2948 - cve-2020-11651 () (June 3, 2020)
- Exploit #2947 - salt-vulnerabilities (Checks for CVE-2020-11651 and CVE-2020-11652) (June 3, 2020)
- Exploit #2656 - SaltStack Salt Master Server Root Key Disclosure (May 12, 2020)
- Exploit #2654 - SaltStack Salt Master/Minion Unauthenticated RCE (May 12, 2020)
- Exploit #2640 - Saltstack 3000.1 - Remote Code Execution (May 11, 2020)
- Exploit #2636 - CVE-2020-11651 (SaltStack exploit compatible with IP lists with customizable payload) (May 11, 2020)
- Exploit #2622 - CVE-2020-11651-poc (PoC exploit of CVE-2020-11651 and CVE-2020-11652) (May 4, 2020)
External References
Related Security Bulletins
- OpenSUSE Linux update for salt
- Multiple vulnerabilities in SaltStack Salt
- Arch Linux update for salt
- Debian update for salt
- Multiple SaltStack Salt vulnerabilities in VMware vRealize Operations Manager
- SaltStack vulnerabilities in Cisco Modeling Labs and Virtual Internet Routing Lab
- OpenSUSE Linux update for salt
- Improper Authentication in salt (Alpine package)
- SUSE update for salt
- SUSE update for salt
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Ubuntu update for salt
- Ubuntu update for salt