Back to search
CVE-2020-16846
Published: Nov 6, 2020
Modified: Oct 21, 2025
PUBLISHED
Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/saltstack/salt/releases
x_refsource_MISC
FEDORA-2020-9e040bd6dd
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2020:1868
vendor-advisory
x_refsource_SUSE
GLSA-202011-13
vendor-advisory
x_refsource_GENTOO
https://www.zerodayinitiative.com/advisories/ZDI-20-1381/
x_refsource_MISC
https://www.zerodayinitiative.com/advisories/ZDI-20-1383/
x_refsource_MISC
https://www.zerodayinitiative.com/advisories/ZDI-20-1380/
x_refsource_MISC
https://www.zerodayinitiative.com/advisories/ZDI-20-1379/
x_refsource_MISC
https://www.zerodayinitiative.com/advisories/ZDI-20-1382/
x_refsource_MISC
[debian-lts-announce] 20201204 [SECURITY] [DLA 2480-1] salt security update
mailing-list
x_refsource_MLIST
DSA-4837
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20220103 [SECURITY] [DLA 2480-2] salt regression update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now