← Back to browse · API

CVE-2020-11652

Severity
MEDIUM
CVSS
6.5
EPSS
0.86178
Risk score
81.16
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-0172, GHSA-VP49-2G4R-M3X3, PYSEC-2020-103
Products
SaltStack:Salt, n/a:n/a n/a
Sources
euvd EUVD-2020-0172
cisa.gov CVE-2020-11652

Description

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

References