November 3, 2021 · Applied Cybernetics Group
CVE-2020-11652 — SaltStack Salt
SaltStack Salt Path Traversal Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- SaltStack
- Product
- Salt
- EPSS
- 99.9th percentile (score 0.937, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-11652
CISA short description
SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
Required action
Apply updates per vendor instructions.