Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 86.2%; technical severity is CVSS 6.5.
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Who should care
- Teams operating Workspaces Server, Ubuntu Linux, Debian Linux +3 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Workspaces Server, Ubuntu Linux, Debian Linux +3 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- VMware Security advisory VMSA-2020-0009
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-22
- Affected versions
- Blackberry Workspaces Server (End Including 7.1.3 | Start Including 8.0.0, End Including 8.2.6 | Version 9.1.0); Canonical Ubuntu Linux (Version 16.04 | Version 18.04); Debian Debian Linux (Version 8.0 | Version 9.0 | Version 10.0); Opensuse Leap (Version 15.1); SaltStack Salt (End Excluding 2019.2.4 | Start Including 3000, End Excluding 3000.2); VMware Application Remote Collector (Version 7.5.0 | Version 8.0.0)
- Fixed versions
- SaltStack Salt (Fixed from 2019.2.4, 3000.2)
- Published
- 30 April 2020
- Attack vector
- Network
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 86.2%
- Signal calculated at 80
External references
- Debian Third-party advisory Msg00027
- Ubuntu Third-party advisory 4459 1
- CISA Government advisory CVE-2020-11652
- GitHub Third-party advisory 3000.2.rst
- Lists Opensuse Third-party advisory Msg00047
- Lists Opensuse Third-party advisory Msg00070
- Packetstormsecurity Third-party advisory Saltstack 3000.1 Remote Code Execution
- Exploit information from packetstormsecurity.com
- Docs Saltstack Technical reference 2019.2.4