CVE-2020-16846
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- SaltStack Salt Shell Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-78
מוצרים מושפעים
saltstack: salt; debian: debian linux; fedoraproject: fedora; opensuse: leap
קישורים
- https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed… Broken LinkVendor Advisory
- https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed… Broken LinkVendor Advisory
- http://packetstormsecurity.com/files/160039/SaltStack-Salt-REST-API-Arbitrary-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/160039/SaltStack-Salt-REST-API-Arbitrary-… ExploitThird Party AdvisoryVDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html Mailing ListThird Party Advisory
- https://github.com/saltstack/salt/releases Release Notes
- https://lists.debian.org/debian-lts-announce/2020/12/msg00007.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00000.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap… Release Notes
- https://security.gentoo.org/glsa/202011-13 Third Party Advisory