CVE-2020-11651
Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
In plain language
AI Act nowCVE-2020-11651 is a serious SaltStack Salt flaw where an internet attacker may be able to call sensitive functions without logging in, potentially taking control of systems Salt manages—if you run SaltStack Salt (especially a salt-master), you should act now.
CVE-2020-11651 is an unauthenticated remote access issue in SaltStack Salt where the salt-master ClearFuncs method-calling path does not properly validate restricted method calls, enabling an attacker to steal user tokens and/or execute arbitrary commands on managed minions.
What to do now
- Check whether your business runs SaltStack Salt with a salt-master component (and whether it is reachable from the network).
- Identify your exact SaltStack Salt version and compare it to the fixed versions.
- Upgrade SaltStack Salt to 2019.2.4 or later (or to 3000.2 or later, as applicable to your release line).
- After upgrading, verify the salt-master service is restarted and that your configuration matches the vendor guidance.
pip install --upgrade 'salt>=2019.2.4'CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-11651 and every CVE in our database. Create a free account — no credit card required.
Create Free Account