Path traversal in Salt - CVE-2020-11652

 

Path traversal in Salt - CVE-2020-11652

Published: May 4, 2020 / Updated: March 22, 2024


Vulnerability identifier: #VU27495
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11652
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the salt-master process ClearFuncs class. A remote authenticated attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Salt
Arch Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Transactional Server
Opensuse
Cisco Virtual Internet Routing Lab Personal Edition
Cisco Modeling Labs Corporate Edition
VMware vRealize Operations Manager (vROps)
salt (Debian package)
salt (Alpine package)
salt-minion (Ubuntu package)
salt-master (Ubuntu package)
salt-common (Ubuntu package)
python2-distro
python3-distro
salt-api (Ubuntu package)
salt-standalone-formulas-configuration
salt-ssh
salt-syndic
salt-fish-completion
salt-cloud
salt-doc
salt-bash-completion
salt-zsh-completion
salt-api
salt
python3-salt
salt-minion
salt-proxy
salt-transactional-update
salt-master
Dell EMC VxRail Appliance

How to mitigate CVE-2020-11652

Install update from vendor's website.

Salt - addressed in versions 2019.2.4, 3000.2
salt (Debian package) - addressed in versions 2016.11.2+ds-1+deb9u3, 2018.3.4+dfsg1-6+deb10u1
salt (Alpine package) - addressed in versions 2019.2.4-r0, 3000.2-r0
salt-minion (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-master (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-common (Ubuntu package) - addressed in versions Ubuntu Pro, 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
python2-distro - update to 1.5.0-3.5.1
python3-distro - update to 1.5.0-3.5.1
Dell EMC VxRail Appliance - update to 7.0.203
salt-api (Ubuntu package) - addressed in versions 2015.8.8+ds-1ubuntu0.1, 2017.7.4+dfsg1-1ubuntu18.04.2
salt-standalone-formulas-configuration - update to 3002.2-37.1
salt-ssh - update to 3002.2-37.1
salt-syndic - update to 3002.2-37.1
salt-fish-completion - update to 3002.2-37.1
salt-cloud - update to 3002.2-37.1
salt-doc - update to 3002.2-37.1
salt-bash-completion - update to 3002.2-37.1
salt-zsh-completion - update to 3002.2-37.1
salt-api - update to 3002.2-37.1
salt - update to 3002.2-37.1
python3-salt - update to 3002.2-37.1
salt-minion - update to 3002.2-37.1
salt-proxy - update to 3002.2-37.1
salt-transactional-update - update to 3002.2-37.1
salt-master - update to 3002.2-37.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins