VDB

CVE-2020-11651

CVE-2020-11651 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

EPSS 96.61% · 99.9th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
96.61%
99.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsalt2015.8.1+ds-2, 2015.8.3+ds-1, 2015.8.3+ds-2
Ubuntu:18.04:LTSsalt0, 2016.11.5+ds-1, 2016.11.8+dfsg1-1
Ubuntu:Pro:14.04:LTSsalt0, 0.16.0-1, 0.16.4-2

Timeline

  • CVE Published
  • May 1, 2020 PoC Published
  • May 3, 2020 PoC Published
  • May 4, 2020 PoC Published
  • May 7, 2020 PoC Published
  • May 12, 2020 PoC Published
  • May 12, 2020 PoC Published
  • May 14, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Nov 3, 2021 CISA KEV Added
Open in Interactive Console →
$ Console Community · 100/wk Open console ›