TROYANOSYVIRUS
Back to CVEs

CVE-2020-16846

CRITICALCISA KEV
9.8

Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published11/6/2020
Last Modified11/7/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorSaltStack
ProductSalt
Vulnerability NameSaltStack Salt Shell Injection Vulnerability
KEV Date Added2021-11-03
Remediation Due Date2022-05-03
Ransomware UseUnknown

Affected Products

debian:debian_linuxfedoraproject:fedoraopensuse:leapsaltstack:salt

Weaknesses (CWE)

CWE-78CWE-78

References

https://github.com/saltstack/salt/releases(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202011-13(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2021/dsa-4837(af854a3a-2127-422b-91ae-364da2661108)
https://www.zerodayinitiative.com/advisories/ZDI-20-1379/(af854a3a-2127-422b-91ae-364da2661108)
https://www.zerodayinitiative.com/advisories/ZDI-20-1380/(af854a3a-2127-422b-91ae-364da2661108)
https://www.zerodayinitiative.com/advisories/ZDI-20-1381/(af854a3a-2127-422b-91ae-364da2661108)
https://www.zerodayinitiative.com/advisories/ZDI-20-1382/(af854a3a-2127-422b-91ae-364da2661108)
https://www.zerodayinitiative.com/advisories/ZDI-20-1383/(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.