id: PYSEC-2020-103 details: An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. affected: - package: name: salt ecosystem: PyPI purl: pkg:pypi/salt ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 2019.2.4 - introduced: "3000" - fixed: "3000.2" versions: - 0.8.7 - 0.8.9 - 0.9.0 - 0.9.1 - 0.9.2 - 0.9.3 - 0.9.4 - 0.9.5 - 0.9.6 - 0.9.7 - 0.9.8 - 0.9.9 - 0.9.9.1 - 0.10.0 - 0.10.1 - 0.10.2 - 0.10.3 - 0.10.4 - 0.10.5 - 0.11.0 - 0.11.1 - 0.12.0 - 0.12.1 - 0.13.0 - 0.13.1 - 0.13.2 - 0.13.3 - 0.14.0 - 0.14.1 - 0.15.0 - 0.15.1 - 0.15.2 - 0.15.3 - 0.15.90 - 0.16.0 - 0.16.1 - 0.16.2 - 0.16.3 - 0.16.4 - 0.17.0rc1 - 0.17.0 - 0.17.1 - 0.17.2 - 0.17.3 - 0.17.4 - 0.17.5 - 2014.1.0rc1 - 2014.1.0rc2 - 2014.1.0rc3 - 2014.1.0 - 2014.1.1 - 2014.1.2 - 2014.1.3 - 2014.1.4 - 2014.1.5 - 2014.1.6 - 2014.1.7 - 2014.1.8 - 2014.1.9 - 2014.1.10 - 2014.1.11 - 2014.1.12 - 2014.1.13 - 2014.7.0rc1 - 2014.7.0rc2 - 2014.7.0rc3 - 2014.7.0rc4 - 2014.7.0rc5 - 2014.7.0rc6 - 2014.7.0rc7 - 2014.7.0 - 2014.7.1 - 2014.7.2 - 2014.7.3 - 2014.7.4 - 2014.7.5 - 2014.7.6 - 2014.7.7 - 2015.2.0rc1 - 2015.2.0rc2 - 2015.5.0 - 2015.5.1 - 2015.5.2 - 2015.5.3 - 2015.5.4 - 2015.5.5 - 2015.5.6 - 2015.5.7 - 2015.5.8 - 2015.5.9 - 2015.5.10 - 2015.5.11 - 2015.8.0rc1 - 2015.8.0rc2 - 2015.8.0rc3 - 2015.8.0rc4 - 2015.8.0rc5 - 2015.8.0 - 2015.8.1 - 2015.8.2 - 2015.8.3 - 2015.8.4 - 2015.8.5 - 2015.8.7 - 2015.8.8 - 2015.8.8.2 - 2015.8.9 - 2015.8.10 - 2015.8.11 - 2015.8.12 - 2015.8.13 - 2016.3.0rc2 - 2016.3.0rc3 - 2016.3.0 - 2016.3.1 - 2016.3.2 - 2016.3.3 - 2016.3.4 - 2016.3.5 - 2016.3.6 - 2016.3.7 - 2016.3.8 - 2016.11.0rc1 - 2016.11.0rc2 - 2016.11.0 - 2016.11.1 - 2016.11.2 - 2016.11.3 - 2016.11.4 - 2016.11.5 - 2016.11.6 - 2016.11.7 - 2016.11.8 - 2016.11.9 - 2016.11.10 - 2017.7.0rc1 - 2017.7.0 - 2017.7.1 - 2017.7.2 - 2017.7.3 - 2017.7.4 - 2017.7.5 - 2017.7.6 - 2017.7.7 - 2017.7.8 - 2018.3.0rc1 - 2018.3.0 - 2018.3.1 - 2018.3.2 - 2018.3.3 - 2018.3.4 - 2018.3.5 - 2019.2.0rc1 - 2019.2.0rc2 - 2019.2.0 - 2019.2.1 - 2019.2.2 - 2019.2.3 - "3000" - "3000.1" references: - type: WEB url: https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html - type: WEB url: https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html - type: WEB url: http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html - type: ADVISORY url: https://www.debian.org/security/2020/dsa-4676 - type: ADVISORY url: http://www.vmware.com/security/advisories/VMSA-2020-0009.html - type: WEB url: http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html - type: WEB url: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG - type: WEB url: https://lists.debian.org/debian-lts-announce/2020/05/msg00027.html - type: WEB url: http://support.blackberry.com/kb/articleDetail?articleNumber=000063758 - type: WEB url: http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html - type: WEB url: https://usn.ubuntu.com/4459-1/ - type: ADVISORY url: https://github.com/advisories/GHSA-vp49-2g4r-m3x3 aliases: - CVE-2020-11652 - GHSA-vp49-2g4r-m3x3 modified: "2020-08-20T01:17:00Z" published: "2020-04-30T17:15:00Z"