Critical severityCISA KEVNVD Advisory· Published Nov 6, 2020· Updated Oct 21, 2025
CVE-2020-16846
CVE-2020-16846
Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
saltPyPI | < 2015.8.13 | 2015.8.13 |
saltPyPI | >= 2016.3.0, < 2016.3.8 | 2016.3.8 |
saltPyPI | >= 2016.11.0, < 2016.11.10 | 2016.11.10 |
saltPyPI | >= 2017.5.0, < 2017.7.8 | 2017.7.8 |
saltPyPI | >= 2018.2.0, < 2018.3.5 | 2018.3.5 |
saltPyPI | >= 2019.2.0, < 2019.2.6 | 2019.2.6 |
saltPyPI | >= 3000.0, < 3000.4 | 3000.4 |
saltPyPI | >= 3001, < 3001.2 | 3001.2 |
saltPyPI | >= 3002, < 3002.1 | 3002.1 |
Affected products
64- SaltStack/SaltStack Saltdescription
- ghsa-coords63 versionspkg:pypi/saltpkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/bind-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/cobbler&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/cobbler&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/grafana-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/image-sync-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/mgr-daemon&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/mgr-daemon&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/mgr-daemon&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/prometheus-exporters-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/prometheus-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/pxe-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/python-susemanager-retail&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/saltboot-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/salt&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2012%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/salt&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/salt&distro=SUSE%20Manager%20Proxy%203.2pkg:rpm/suse/salt&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/salt-netapi-client&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacecmd&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/spacecmd&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-admin&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-branding&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-search&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-build-keys&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/susemanager-build-keys&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-doc-indexes&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-docs_en&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-schema&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-sls&distro=SUSE%20Manager%20Server%20Module%204.1
< 2015.8.13+ 62 more
- (no CPE)range: < 2015.8.13
- (no CPE)range: < 3000-lp151.5.30.1
- (no CPE)range: < 3000-lp152.3.15.1
- (no CPE)range: < 0.1.1603299886.60e4bcf-3.3.2
- (no CPE)range: < 2.2.2-0.68.12.1
- (no CPE)range: < 2.2.2-0.68.12.1
- (no CPE)range: < 0.3.0-3.3.2
- (no CPE)range: < 0.1.1602150122.f08af0a-3.6.2
- (no CPE)range: < 4.1.3-5.20.1
- (no CPE)range: < 4.1.3-5.20.1
- (no CPE)range: < 4.1.3-2.6.3
- (no CPE)range: < 0.8.0-3.16.2
- (no CPE)range: < 0.3.0-3.3.1
- (no CPE)range: < 0.1.1602490840.4f32148-3.3.2
- (no CPE)range: < 2016.11.10-6.41.1
- (no CPE)range: < 2016.11.10-10.17.1
- (no CPE)range: < 2016.11.10-6.3.3
- (no CPE)range: < 1.0.1602150122.f08af0a-3.3.2
- (no CPE)range: < 0.1.1602150122.f08af0a-3.6.2
- (no CPE)range: < 2016.11.4-48.13.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 3000-6.51.1
- (no CPE)range: < 3000-4.20.1
- (no CPE)range: < 3000-6.51.1
- (no CPE)range: < 3000-4.20.1
- (no CPE)range: < 3000-6.51.1
- (no CPE)range: < 3000-4.20.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 2016.11.10-43.63.1
- (no CPE)range: < 2016.11.10-43.63.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 0.18.0-15.7.5
- (no CPE)range: < 4.1.8-18.72.1
- (no CPE)range: < 4.1.8-18.72.1
- (no CPE)range: < 4.1.8-4.9.2
- (no CPE)range: < 4.1.8-4.9.2
- (no CPE)range: < 4.1.7-3.6.3
- (no CPE)range: < 4.1.16-4.11.5
- (no CPE)range: < 4.1.16-4.11.5
- (no CPE)range: < 4.1.11-3.9.6
- (no CPE)range: < 4.1.7-27.38.1
- (no CPE)range: < 4.1.7-27.38.1
- (no CPE)range: < 4.1.7-4.6.4
- (no CPE)range: < 4.1.7-4.6.4
- (no CPE)range: < 2.8.78.31-3.56.1
- (no CPE)range: < 4.0.39-3.45.1
- (no CPE)range: < 4.1.22-3.16.4
- (no CPE)range: < 4.1.3-3.3.7
- (no CPE)range: < 4.1.19-3.9.5
- (no CPE)range: < 4.1.19-3.9.5
- (no CPE)range: < 15.2.2-3.6.3
- (no CPE)range: < 15.2.2-3.6.3
- (no CPE)range: < 4.1.21-3.11.6
- (no CPE)range: < 4.1-11.17.1
- (no CPE)range: < 4.1-11.17.1
- (no CPE)range: < 4.1.15-3.11.2
- (no CPE)range: < 4.1.17-3.13.6
Patches
Vulnerability mechanics
References
30- lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.htmlghsavendor-advisoryx_refsource_SUSEWEB
- github.com/advisories/GHSA-qr38-h96j-2j3wghsaADVISORY
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMA/mitrevendor-advisoryx_refsource_FEDORA
- nvd.nist.gov/vuln/detail/CVE-2020-16846ghsaADVISORY
- security.gentoo.org/glsa/202011-13ghsavendor-advisoryx_refsource_GENTOOWEB
- www.debian.org/security/2021/dsa-4837ghsavendor-advisoryx_refsource_DEBIANWEB
- packetstormsecurity.com/files/160039/SaltStack-Salt-REST-API-Arbitrary-Command-Execution.htmlghsax_refsource_MISCWEB
- github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2020-104.yamlghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2019.2.6.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3000.4.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3001.2.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3002.1.rstghsaWEB
- github.com/saltstack/salt/releasesghsax_refsource_MISCWEB
- lists.debian.org/debian-lts-announce/2020/12/msg00007.htmlghsamailing-listx_refsource_MLISTWEB
- lists.debian.org/debian-lts-announce/2022/01/msg00000.htmlghsamailing-listx_refsource_MLISTWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMAghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMAghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalogghsaWEB
- www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cvesghsaWEB
- www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/mitrex_refsource_CONFIRM
- www.zerodayinitiative.com/advisories/ZDI-20-1379ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1379/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1380ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1380/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1381ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1381/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1382ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1382/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1383ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1383/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.