CRITICAL

CVE-2020-16846

Debian Debian Linux 2020-11-06 CVSS v3.1
CVSS
9.8
KEV

Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

Summary dbcve.org

A shell injection vulnerability in SaltStack Salt's API (when the SSH client is enabled) allows remote attackers to execute arbitrary shell commands by sending crafted web requests to the Salt API. This is a critical remote code execution (RCE) vulnerability with a CVSS score of 9.8.

Mitigation

Apply the vendor patch (upgrade to SaltStack Salt version 3002.2 or later). If immediate patching is not possible, restrict network access to the Salt API, disable the SSH client if not required, and implement strict input validation on all API endpoints.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

99.59%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE