MEDIUM 6.5 PyPI KEV

SaltStack Salt is vulnerable Arbitrary Directory Access

GHSA-vp49-2g4r-m3x3 · CVE-2020-11652 · PYSEC-2020-103

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

Ready to move

Start Securing

Free, no credit card | First findings in minutes