Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2020-11651
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
SaltStack Salt 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SaltStack Salt是SaltStack公司的一套开源的用于管理基础架构的工具。该工具提供配置管理、远程执行等功能。 SaltStack Salt 2019.2.4之前版本和3000.2之前的3000.x版本中存在安全漏洞,该漏洞源于salt-master进程的ClearFuncs类没有正确验证方法的调用。远程攻击者可利用该漏洞检索用户令牌或执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2020-11651
#POC DescriptionSource LinkShenlong Link
1Checks for CVE-2020-11651 and CVE-2020-11652https://github.com/chef-cft/salt-vulnerabilitiesPOC Details
2Salt security backports for CVE-2020-11651 & CVE-2020-11652https://github.com/rossengeorgiev/salt-security-backportsPOC Details
3Nonehttps://github.com/dozernz/cve-2020-11651POC Details
4CVE-2020-11651: Proof of Concepthttps://github.com/0xc0d/CVE-2020-11651POC Details
5PoC exploit of CVE-2020-11651 and CVE-2020-11652https://github.com/jasperla/CVE-2020-11651-pocPOC Details
6CVE-2020-11651&&CVE-2020-11652 EXPhttps://github.com/bravery9/SaltStack-ExpPOC Details
7PoC for CVE-2020-11651https://github.com/kevthehermit/CVE-2020-11651POC Details
8Nonehttps://github.com/lovelyjuice/cve-2020-11651-exp-plusPOC Details
9CVE-2020-11651&&CVE-2020-11652 EXPhttps://github.com/ssrsec/CVE-2020-11651-CVE-2020-11652-EXPPOC Details
10PoC for CVE-2020-11651https://github.com/RakhithJK/CVE-2020-11651POC Details
11CVE-2020-11651&&CVE-2020-11652 EXPhttps://github.com/5l1v3r1/SaltStack-Exp-1POC Details
12Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.https://github.com/appcheck-ng/salt-rce-scanner-CVE-2020-11651-CVE-2020-11652POC Details
13Nonehttps://github.com/puckiestyle/cve-2020-11651POC Details
14Repository that contains a CVE-2020-11651 Exploit updated to work with the latest versions of python.https://github.com/hardsoftsecurity/CVE-2020-11651-PoCPOC Details
15A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd and /etc/shadow.https://github.com/Drew-Alleman/CVE-2020-11651POC Details
16Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/SaltStack%20%E6%B0%B4%E5%B9%B3%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2020-11651.mdPOC Details
17Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Saltstack%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2020-11651%2011652.mdPOC Details
18https://github.com/vulhub/vulhub/blob/master/saltstack/CVE-2020-11651/README.mdPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2020-11651
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2020-11651

No comments yet


Leave a comment