Junglewise Threat Intelligence

CVE-2020-16846: PYSEC-2020-104 - An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can resul

CVE-2020-16846 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-11-06

Technologies: Saltstack Salt. Vendors: PyPI, Saltstack.

Executive brief

SaltStack Salt through version 3002 is vulnerable to shell injection via the Salt API. An unauthenticated remote attacker can execute arbitrary code by sending crafted web requests when the SSH client is enabled.

Affected products

  • SaltStack Salt through 3002

Timeline

  • 2020-11-03: disclosed: SaltStack publicly disclosed the vulnerability.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • exploited: Reported as exploited in the wild.

Related threats