CRITICAL
CVE-2020-16846
CVSS
9.8
KEV
Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Summary dbcve.org
A shell injection vulnerability in SaltStack Salt's API (when the SSH client is enabled) allows remote attackers to execute arbitrary shell commands by sending crafted web requests to the Salt API. This is a critical remote code execution (RCE) vulnerability with a CVSS score of 9.8.
Mitigation
Apply the vendor patch (upgrade to SaltStack Salt version 3002.2 or later). If immediate patching is not possible, restrict network access to the Salt API, disable the SSH client if not required, and implement strict input validation on all API endpoints.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
99.59%
Probability of exploitation in next 30 days
99.9th percentile
References
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html
Mailing List, Third Party Advisory
http://packetstormsecurity.com/files/160039/SaltStack-Salt-REST-API-Arbitrary-Command-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://github.com/saltstack/salt/releases
Release Notes
https://lists.debian.org/debian-lts-announce/2020/12/msg00007.html
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/01/msg00000.html
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMA/
Release Notes
https://security.gentoo.org/glsa/202011-13
Third Party Advisory
https://www.debian.org/security/2021/dsa-4837
Mailing List, Third Party Advisory
https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/
Broken Link, Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-1379/
Third Party Advisory, VDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-20-1380/
Third Party Advisory, VDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-20-1381/
Third Party Advisory, VDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-20-1382/
Third Party Advisory, VDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-20-1383/
Third Party Advisory, VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-16846
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.