November 3, 2021 · Applied Cybernetics Group
CVE-2020-11651 — SaltStack Salt
SaltStack Salt Authentication Bypass Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- SaltStack
- Product
- Salt
- EPSS
- 99.9th percentile (score 0.942, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-11651
CISA short description
SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
Required action
Apply updates per vendor instructions.