Tracker / CVE-2020-11652
CVE-2020-11652
Exploited Medium 6.5
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Affected products and versions
| blackberry | workspaces_server |
|---|---|
| blackberry | workspaces_server · … → 7.1.3 |
| blackberry | workspaces_server · 8.0.0 → 8.2.6 |
| canonical | ubuntu_linux |
| debian | debian_linux |
| opensuse | leap |
| saltstack | salt · … → 2019.2.4 |
| saltstack | salt · 3000 → 3000.2 |
| vmware | application_remote_collector |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.