Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-11651
Description:An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
Test IDs: 1.3.6.1.4.1.25623.1.0.892223   1.3.6.1.4.1.25623.1.1.4.2020.1150.1   1.3.6.1.4.1.25623.1.0.853131   1.3.6.1.4.1.25623.1.1.4.2020.1151.1   1.3.6.1.4.1.25623.1.1.4.2020.1973.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-11651
Cisco Security Advisory: 20200528 SaltStack FrameWork Vulnerabilities Affecting Cisco Products
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG
Debian Security Information: DSA-4676 (Google Search)
https://www.debian.org/security/2020/dsa-4676
http://packetstormsecurity.com/files/157560/Saltstack-3000.1-Remote-Code-Execution.html
http://packetstormsecurity.com/files/157678/SaltStack-Salt-Master-Minion-Unauthenticated-Remote-Code-Execution.html
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
https://lists.debian.org/debian-lts-announce/2020/05/msg00027.html
SuSE Security Announcement: openSUSE-SU-2020:0564 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html
SuSE Security Announcement: openSUSE-SU-2020:1074 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00070.html
https://usn.ubuntu.com/4459-1/




© 1998-2025 E-Soft Inc. All rights reserved.