Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11652

Опубликовано: 30 апр. 2020
Источник: debian

Описание

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
saltfixed3000.2+dfsg1-1package

Примечания

  • https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst

  • Fixed by: https://github.com/saltstack/salt/commit/cce7abad9c22d9d50ccee2813acabff8deca35dd

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

CVSS3: 6.5
redhat
почти 6 лет назад

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

CVSS3: 6.5
nvd
почти 6 лет назад

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

CVSS3: 6.5
github
больше 3 лет назад

SaltStack Salt is vulnerable Arbitrary Directory Access

CVSS3: 6.5
fstec
почти 6 лет назад

Уязвимость компонента ClearFuncs системы управления конфигурациями и удалённого выполнения операций SaltStack, позволяющая нарушителю получить доступ к конфиденциальным данным