Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-11652 PoC — SaltStack Salt 路径遍历漏洞

Source
Associated Vulnerability
Title:SaltStack Salt 路径遍历漏洞 (CVE-2020-11652)
Description:An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Description
This is a fix POC CVE-2020-11651 & CVE-2020-11651
Readme
# CVE-2020-11652-CVE-2020-11652-POC
This is a fix POC CVE-2020-11651 & CVE-2020-11651

Original version: https://github.com/Al1ex/CVE-2020-11652

Error Fixed: `TransportWarning: Unclosed transport! <salt.transport.zeromq.RequestClient object at 0x7f2105513690>`

`pip3 install salt`

RCE

`python3 CVE-2020-11652.py --master <target ip> --port <target port> --exec-choose master --exec-cmd 'whoami'`
File Snapshot

[4.0K] /data/pocs/9b04f08a80551cf273c78b97dfd4d3f5ffbc7a3d ├── [6.9K] CVE-2020-11652-fix.py └── [ 403] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →