ZeroHour

CVE-2020-16846

KEV PoC large

Shell Injection in SaltStack Salt API Enables Remote Command Execution

CISA: SaltStack Salt Shell Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2020-16846 is a shell/command injection flaw (CWE-78) in the SSH client of SaltStack Salt's REST API (salt-api), affecting Salt through version 3002. An attacker triggers it by sending crafted web requests to salt-api when the SSH client is enabled, causing injected commands to run on the Salt master with the privileges of the salt-api process. The CVSS vector (network vector, low complexity, no privileges or user interaction required) indicates remote, unauthenticated code execution, and the flaw was commonly chained with the related salt-api authentication bypass CVE-2020-25592 for full unauthenticated takeover. Anyone running a vulnerable Salt master with salt-api enabled is exposed, including Salt packages shipped by Debian, Fedora, and openSUSE Leap. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2021-11-03), carries a 99.6% EPSS probability of exploitation, and a public PoC is available.

What to do: Upgrade Salt to 3002.2, 3001.4, or 3000.6 (or later), or install updated Salt packages from Debian, Fedora, or openSUSE; note this flaw is typically exploited together with CVE-2020-25592, so patch both. Until patched, restrict network access to salt-api (default port 8000), require authentication, and disable the SSH client if it is not needed. Given the CISA KEV listing, treat any unpatched salt-api instance as potentially compromised and review it for signs of exploitation.

Affected
SaltStack Saltthrough 3002 (all releases up to and including 3002)
Debian Linux
Fedora Project Fedora
openSUSE Leap
Estimated exposure
largetens of thousands of internet-exposed Salt masters/API endpoints, from public internet scans — Public internet-wide scans of Salt's default master ports (4505/4506) and salt-api (port 8000) have repeatedly shown thousands to tens of thousands of exposed Salt deployments, and Salt's broader data-center/orchestration install base is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

CISA Known Exploited Vulnerability
Affected
SaltStack Salt
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
saltstackdebianfedoraprojectopensuse
Products
salt, debian linux, fedora, leap
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.