CVE-2020-11651
is CVE-2020-11651real, exploitable, or a false positive? Here's the community ground truth.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
References
Published
Embed this verdict
[](https://www.truepositive.app/cve/CVE-2020-11651)<a href="https://www.truepositive.app/cve/CVE-2020-11651"><img src="https://www.truepositive.app/cve/CVE-2020-11651/badge.svg" alt="TruePositive verdict for CVE-2020-11651"></a>Live badge — updates automatically as the community verdict changes.
Community ground truth
Community verdict
3 verdictsto add your verdict.
In line with its CVSS base score.
Field notes & remediation
Verdicts are the quick signal — notes are the evidence and fixes behind them.
No notes yet — be the first to share what you saw or a fix that worked.