salt: sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection
Published Nov 6, 2020 ·Due May 3, 2022
9.8
CRITICALCVSS 3.1
EPSS 99.59%
Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Affected products
No data.
Configuration 1
- < 2015.8.10
- ≥ 2015.8.11 · < 2015.8.13
- ≥ 2016.3.0 · < 2016.3.4
- ≥ 2016.3.5 · < 2016.3.6
- ≥ 2016.3.7 · < 2016.3.8
- ≥ 2016.11.0 · < 2016.11.3
- ≥ 2016.11.4 · < 2016.11.6
- ≥ 2016.11.7 · < 2016.11.10
- ≥ 2017.5.0 · < 2017.7.4
- ≥ 2017.7.5 · < 2017.7.8
- ≥ 2018.2.0 · < 2018.3.5
- ≥ 2019.2.0 · < 2019.2.5
- ≥ 3000.0 · < 3000.3
- 3001
- 3002
Configuration 2
- 9.0
- 10.0
Configuration 3
- 31
No data.
Red Hat Ceph Storage 2
salt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | salt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Ceph Storage 2 shipped salt for the usage of Red Hat Storage Console 2 (RHSCON-2), which required salt to administrate ceph nodes. RHSCON-2 has reached End Of Life, hence salt is no longer used and supported. Therefore, the salt package provided by Red Hat Ceph Storage 2 has been marked as 'will not fix'.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 99.59% (0.99585) | 99.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 99.59% (0.99585) | 99.94th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.39% (0.94387) | 99.97th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.86% (0.96855) | 99.76th | v3 (v2023.03.01) |
| Jun 3, 2024 | 97.34% (0.97343) | 99.89th | v3 (v2023.03.01) |
| Jan 8, 2024 | 97.47% (0.97467) | 99.96th | v3 (v2023.03.01) |
| Dec 10, 2023 | 97.52% (0.97516) | 99.98th | v3 (v2023.03.01) |
| Sep 29, 2023 | 97.53% (0.97532) | 99.99th | v3 (v2023.03.01) |
| Aug 18, 2023 | 97.51% (0.97514) | 99.97th | v3 (v2023.03.01) |
| Jul 23, 2023 | 97.53% (0.97532) | 99.98th | v3 (v2023.03.01) |
| Jul 10, 2023 | 97.54% (0.97541) | 99.99th | v3 (v2023.03.01) |
| Jun 13, 2023 | 97.53% (0.97531) | 99.98th | v3 (v2023.03.01) |
| May 18, 2023 | 97.52% (0.97517) | 99.97th | v3 (v2023.03.01) |
| May 5, 2023 | 97.53% (0.97526) | 99.98th | v3 (v2023.03.01) |
| Apr 21, 2023 | 97.54% (0.97541) | 99.99th | v3 (v2023.03.01) |
| Apr 8, 2023 | 97.54% (0.97535) | 99.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.55% (0.97549) | 99.99th | v3 (v2023.03.01) |
| Mar 6, 2023 | 87.12% (0.87118) | 99.73th | v2 (v2022.01.01) |
| Feb 4, 2022 | 87.12% (0.87118) | 99.68th | v2 (v2022.01.01) |
| Feb 3, 2022 | 52.83% (0.52827) | 99.07th | v1 |
| Jan 4, 2022 | 52.83% (0.52827) | 99.68th | v1 |
| Sep 1, 2021 | 51.09% (0.51093) | 99.67th | v1 |
| Apr 14, 2021 | 51.09% (0.51093) | 0.00th | v1 |
References (31)
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/160039/SaltStack-Salt-REST-API-Arbitrary-Command-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2020-16846 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1895449 Issue Tracking
- https://docs.saltstack.com/en/latest/topics/releases/2019.2.6.html
- https://docs.saltstack.com/en/latest/topics/releases/3000.4.html
- https://docs.saltstack.com/en/latest/topics/releases/3001.2.html
- https://docs.saltstack.com/en/latest/topics/releases/3002.1.html
- https://github.com/advisories/GHSA-qr38-h96j-2j3w Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2020-104.yaml
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2019.2.6.rst#L10
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3000.4.rst#L10
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3001.2.rst#L10
- https://github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3002.1.rst#L12
- https://github.com/saltstack/salt/releases x_refsource_MISCRelease Notes
- https://lists.debian.org/debian-lts-announce/2020/12/msg00007.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMA vendor-advisoryx_refsource_FEDORARelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMA
- https://nvd.nist.gov/vuln/detail/CVE-2020-16846
- https://security.gentoo.org/glsa/202011-13 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-16846 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2020-16846
- https://www.debian.org/security/2021/dsa-4837 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves x_refsource_CONFIRMBroken LinkVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1379 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-20-1380 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-20-1381 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-20-1382 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-20-1383 x_refsource_MISCThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.