Back

CRITICAL KEV

salt: sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection

Published Nov 6, 2020 ·Due May 3, 2022

Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

Affected products

Remediation

Red Hat statement

Red Hat Ceph Storage 2 shipped salt for the usage of Red Hat Storage Console 2 (RHSCON-2), which required salt to administrate ceph nodes. RHSCON-2 has reached End Of Life, hence salt is no longer used and supported. Therefore, the salt package provided by Red Hat Ceph Storage 2 has been marked as 'will not fix'.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Metrics

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 6, 2020
Updated Oct 21, 2025
Reserved Aug 4, 2020
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 3, 2020
GHSA-QR38-H96J-2J3W