CVE-2020-16846

saltstack/salt
on github

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:saltstack:salt:3001:*:*:*:*:*:*:*n/an/a3001
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2019.2.0 (including)2019.2.5*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*3000.0 (including)3000.3*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2018.2.0 (including)2018.3.5*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.3.7 (including)2016.3.8*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2017.7.5 (including)2017.7.8*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2017.5.0 (including)2017.7.4*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.11.7 (including)2016.11.10*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.11.4 (including)2016.11.6*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*n/a2015.8.10*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2015.8.11 (including)2015.8.13*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.3.0 (including)2016.3.4*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.3.5 (including)2016.3.6*
cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*2016.11.0 (including)2016.11.3*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0

External Links