← All CVEs

CVE-2020-16846

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

9.8
CVSS
99.6%
EPSS (exploit prob.)
100th
EPSS percentile
2020-11-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
saltstacksalt< 2015.8.10
saltstacksalt>= 2015.8.11, < 2015.8.13
saltstacksalt>= 2016.3.0, < 2016.3.4
saltstacksalt>= 2016.3.5, < 2016.3.6
saltstacksalt>= 2016.3.7, < 2016.3.8
saltstacksalt>= 2016.11.0, < 2016.11.3
saltstacksalt>= 2016.11.4, < 2016.11.6
saltstacksalt>= 2016.11.7, < 2016.11.10
saltstacksalt>= 2017.5.0, < 2017.7.4
saltstacksalt>= 2017.7.5, < 2017.7.8
saltstacksalt>= 2018.2.0, < 2018.3.5
saltstacksalt>= 2019.2.0, < 2019.2.5
saltstacksalt>= 3000.0, < 3000.3
saltstacksalt3001
saltstacksalt3002
debiandebian_linux9.0
debiandebian_linux10.0
fedoraprojectfedora31
opensuseleap15.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-16846