EUVD-2020-0172
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 3 Nov 2021. Evidence sources: cisa_kev.
- ENISA score
- 6.5 · CVSS 3.1
- Advisory evidence
- 15 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_suse · SUSE-SU-2020:1971-1Security update for Salt
- csaf_opensuse · openSUSE-SU-2020:1074-1Security update for salt
- csaf_suse · SUSE-SU-2020:1392-1Security update for salt
- csaf_suse · SUSE-SU-2020:1150-1Security update for salt
- csaf_suse · SUSE-SU-2020:1974-1Security update for salt
- csaf_opensuse · openSUSE-SU-2021:2106-1Security update for salt
- csaf_opensuse · openSUSE-SU-2021:0899-1Security update for salt
- csaf_opensuse · openSUSE-SU-2020:0564-1Security update for salt
- csaf_suse · SUSE-SU-2021:2106-1Security update for salt
- csaf_suse · SUSE-SU-2020:1973-1Security update for Salt
- csaf_suse · SUSE-SU-2021:2105-1Security update for salt
- csaf_suse · SUSE-SU-2020:1147-1Security update for salt
- csaf_suse · SUSE-SU-2020:1151-1Security update for salt
