A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2020-11652

SaltStack Salt Path Traversal Vulnerability

Published
2021-11-03
Modified
2026-07-31
Sources
cisa-kev

Summary

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.