Back

HIGH KEV

salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths

Published Apr 30, 2020 ·Due May 3, 2022

Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Affected products

Remediation

Red Hat statement

Red Hat Ceph Storage 2 shipped salt for the usage of Red Hat Storage Console 2(RHSCON-2), which required salt to administrate ceph nodes. RHSCON-2 has reached End Of Life, hence salt is no longer used and supported. Therefore, the salt package provided by Red Hat Ceph Storage 2 has been marked as 'will not fix'.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2020
Updated Oct 21, 2025
Reserved Apr 8, 2020
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 29, 2020
ENISA EUVD
Assigner mitre
Published Apr 30, 2020
Updated Oct 21, 2025
Exploited since Nov 3, 2021
EUVD-2020-0172 GHSA-VP49-2G4R-M3X3