CVE-2020-16846: SaltStack Salt Shell Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 99.6% chance of exploitation in the next 30 days.
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 31 only
- Opensuse Leap: version 15.1 only
- SaltStack Salt: before 2015.8.10 (fixed in 2015.8.10); from 2015.8.11, before 2015.8.13 (fixed in 2015.8.13); from 2016.3.0, before 2016.3.4 (fixed in 2016.3.4); from 2016.3.5, before 2016.3.6 (fixed in 2016.3.6); from 2016.3.7, before 2016.3.8 (fixed in 2016.3.8); from 2016.11.0, before 2016.11.3 (fixed in 2016.11.3); …
Published 2020-11-06. Last modified 2026-06-17.