CVE-2020-25592: Debian Linux

Critical severity, CVSS 9.8. EPSS: 57.7% chance of exploitation in the next 30 days.

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • SaltStack Salt: before 2015.8.10 (fixed in 2015.8.10); from 2015.8.11, before 2015.8.13 (fixed in 2015.8.13); from 2016.3.0, before 2016.3.4 (fixed in 2016.3.4); from 2016.3.5, before 2016.3.6 (fixed in 2016.3.6); from 2016.3.7, before 2016.3.8 (fixed in 2016.3.8); from 2016.11.0, before 2016.11.3 (fixed in 2016.11.3); …

Published 2020-11-06. Last modified 2026-06-17.