CVE-2020-16846
KEV PoC largeShell Injection in SaltStack Salt API Enables Remote Command Execution
CISA: SaltStack Salt Shell Injection Vulnerability
CVE-2020-16846 is a shell/command injection flaw (CWE-78) in the SSH client of SaltStack Salt's REST API (salt-api), affecting Salt through version 3002. An attacker triggers it by sending crafted web requests to salt-api when the SSH client is enabled, causing injected commands to run on the Salt master with the privileges of the salt-api process. The CVSS vector (network vector, low complexity, no privileges or user interaction required) indicates remote, unauthenticated code execution, and the flaw was commonly chained with the related salt-api authentication bypass CVE-2020-25592 for full unauthenticated takeover. Anyone running a vulnerable Salt master with salt-api enabled is exposed, including Salt packages shipped by Debian, Fedora, and openSUSE Leap. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2021-11-03), carries a 99.6% EPSS probability of exploitation, and a public PoC is available.
What to do: Upgrade Salt to 3002.2, 3001.4, or 3000.6 (or later), or install updated Salt packages from Debian, Fedora, or openSUSE; note this flaw is typically exploited together with CVE-2020-25592, so patch both. Until patched, restrict network access to salt-api (default port 8000), require authentication, and disable the SSH client if it is not needed. Given the CISA KEV listing, treat any unpatched salt-api instance as potentially compromised and review it for signs of exploitation.
| SaltStack Salt | through 3002 (all releases up to and including 3002) |
| Debian Linux | — |
| Fedora Project Fedora | — |
| openSUSE Leap | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
- Affected
- SaltStack Salt
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- saltstackdebianfedoraprojectopensuse
- Products
- salt, debian linux, fedora, leap
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.