salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths
Published Apr 30, 2020 ·Due May 3, 2022
7.1
HIGHCVSS 4.0
EPSS 86.18%
Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Affected products
No data.
Configuration 1
Configuration 3
- 8.0
- 9.0
- 10.0
Configuration 4
- 16.04
- 18.04
Configuration 5
- ≤ 7.1.3
- ≥ 8.0.0 · ≤ 8.2.6
- 9.1.0
Configuration 6
- 7.5.0
- 8.0.0
No data.
Red Hat Ceph Storage 2
salt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | salt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Ceph Storage 2 shipped salt for the usage of Red Hat Storage Console 2(RHSCON-2), which required salt to administrate ceph nodes. RHSCON-2 has reached End Of Life, hence salt is no longer used and supported. Therefore, the salt package provided by Red Hat Ceph Storage 2 has been marked as 'will not fix'.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (23)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://support.blackberry.com/kb/articleDetail?articleNumber=000063758 x_refsource_MISCThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2020-0009.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-11652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1832420 Issue Tracking
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html x_refsource_MISCVendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/3000.2.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0172 Advisory
- https://github.com/advisories/GHSA-vp49-2g4r-m3x3 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2020-103.yaml
- https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst x_refsource_MISCThird Party Advisory
- https://labs.f-secure.com/advisories/saltstack-authorization-bypass
- https://lists.debian.org/debian-lts-announce/2020/05/msg00027.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-11652
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG vendor-advisoryx_refsource_CISCOThird Party Advisory
- https://usn.ubuntu.com/4459-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11652 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2020-11652
- https://www.debian.org/security/2020/dsa-4676 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.