PromptRiskDBThreat intelligence atlas
AI Vulnerability Context

CVE-2020-11651 - SaltStack Salt

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are n...

AI Vulnerability ContextCISA KEVSaltStack

Record summary

A quick snapshot of what this page covers.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEV
CVE ID
CVE-2020-11651
Vendor/project
SaltStack
Product
Salt
Vulnerability name
SaltStack Salt Authentication Bypass Vulnerability
Date added
2021-11-03
Due date
2022-05-03
Known ransomware campaign use
Unknown

Exploit context

What the vulnerability is about.

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Source

Where this page information comes from.