Path traversal in Salt - CVE-2020-11652
Published: May 4, 2020 / Updated: March 22, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the salt-master process ClearFuncs class. A remote authenticated attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Arch Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Transactional Server
Opensuse
Cisco Virtual Internet Routing Lab Personal Edition
Cisco Modeling Labs Corporate Edition
VMware vRealize Operations Manager (vROps)
salt (Debian package)
salt (Alpine package)
salt-minion (Ubuntu package)
salt-master (Ubuntu package)
salt-common (Ubuntu package)
python2-distro
python3-distro
salt-api (Ubuntu package)
salt-standalone-formulas-configuration
salt-ssh
salt-syndic
salt-fish-completion
salt-cloud
salt-doc
salt-bash-completion
salt-zsh-completion
salt-api
salt
python3-salt
salt-minion
salt-proxy
salt-transactional-update
salt-master
Dell EMC VxRail Appliance
How to mitigate CVE-2020-11652
salt (Debian package) - addressed in versions 2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1
salt (Alpine package) - addressed in versions 2019.2.4-r0, 3000.2-r0
salt-minion (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-master (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-common (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
python2-distro - update to 1.5.0-3.5.1
python3-distro - update to 1.5.0-3.5.1
Dell EMC VxRail Appliance - update to 7.0.203
salt-api (Ubuntu package) - addressed in versions 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-standalone-formulas-configuration - update to 3002.2-37.1
salt-ssh - update to 3002.2-37.1
salt-syndic - update to 3002.2-37.1
salt-fish-completion - update to 3002.2-37.1
salt-cloud - update to 3002.2-37.1
salt-doc - update to 3002.2-37.1
salt-bash-completion - update to 3002.2-37.1
salt-zsh-completion - update to 3002.2-37.1
salt-api - update to 3002.2-37.1
salt - update to 3002.2-37.1
python3-salt - update to 3002.2-37.1
salt-minion - update to 3002.2-37.1
salt-proxy - update to 3002.2-37.1
salt-transactional-update - update to 3002.2-37.1
salt-master - update to 3002.2-37.1
Links to Public Exploits and PoC-codes
- Exploit #9623 - CVE-2020-11652-POC (This is a fix POC CVE-2020-11651 & CVE-2020-11651) (March 22, 2024)
- Exploit #4967 - CVE-2020-11652 (CVE-2020-11652 & CVE-2020-11651) (December 28, 2020)
- Exploit #4895 - salt-rce-scanner-CVE-2020-11651-CVE-2020-11652 (Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.) (December 2, 2020)
- Exploit #2946 - salt-vulnerabilities (Checks for CVE-2020-11651 and CVE-2020-11652) (June 3, 2020)
- Exploit #2949 - SaltStack-Exp (CVE-2020-11651&&CVE-2020-11652 EXP) (June 3, 2020)
- Exploit #2951 - SaltStack-Exp (CVE-2020-11651&&CVE-2020-11652 EXP) (June 3, 2020)
- Exploit #2961 - CVE-2020-11651-CVE-2020-11652-EXP (CVE-2020-11651&&CVE-2020-11652 EXP) (June 3, 2020)
- Exploit #2981 - salt-security-backports (Salt security backports for CVE-2020-11651 & CVE-2020-11652) (June 3, 2020)
- Exploit #2996 - CVE-2020-11652 (saltstack CVE-2020-11652 ) (June 3, 2020)
- Exploit #2653 - SaltStack Salt Master/Minion Unauthenticated RCE (May 12, 2020)
- Exploit #2655 - SaltStack Salt Master Server Root Key Disclosure (May 12, 2020)
- Exploit #2639 - Saltstack 3000.1 - Remote Code Execution (May 11, 2020)
- Exploit #2635 - CVE-2020-11651 (SaltStack exploit compatible with IP lists with customizable payload) (May 11, 2020)
- Exploit #2623 - CVE-2020-11651-poc (PoC exploit of CVE-2020-11651 and CVE-2020-11652) (May 4, 2020)
External References
Related Security Bulletins
- OpenSUSE Linux update for salt
- Multiple vulnerabilities in SaltStack Salt
- Arch Linux update for salt
- Debian update for salt
- Multiple SaltStack Salt vulnerabilities in VMware vRealize Operations Manager
- SaltStack vulnerabilities in Cisco Modeling Labs and Virtual Internet Routing Lab
- OpenSUSE Linux update for salt
- Path traversal in salt (Alpine package)
- SUSE update for salt
- SUSE update for salt
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Ubuntu update for salt
- Ubuntu update for salt