← Back

CVE-2020-16846

Published: Nov 6, 2020Modified: Nov 7, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

Affected (19)

Products: Saltstack: Salt · Debian: Debian Linux · Fedoraproject: Fedora · +1 more
Show all products
1 product
Salt
1 product
Debian Linux
1 product
Fedora
1 product
Leap
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Saltstack
Before 2015.8.10
From 2015.8.11 to 2015.8.13
From 2016.11.0 to 2016.11.3
From 2016.11.4 to 2016.11.6
From 2016.11.7 to 2016.11.10
From 2016.3.0 to 2016.3.4
From 2016.3.5 to 2016.3.6
From 2016.3.7 to 2016.3.8
From 2017.5.0 to 2017.7.4
From 2017.7.5 to 2017.7.8
From 2018.2.0 to 2018.3.5
From 2019.2.0 to 2019.2.5
From 3000.0 to 3000.3
Version 3001
Version 3002
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 31
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1

References (29)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Release Notes
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.