Critical severity9.8CISA KEVNVD Advisory· Published Nov 6, 2020· Updated Jun 17, 2026
CVE-2020-16846
CVE-2020-16846
Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
saltPyPI | < 2015.8.13 | 2015.8.13 |
saltPyPI | >= 2016.3.0, < 2016.3.8 | 2016.3.8 |
saltPyPI | >= 2016.11.0, < 2016.11.10 | 2016.11.10 |
saltPyPI | >= 2017.5.0, < 2017.7.8 | 2017.7.8 |
saltPyPI | >= 2018.2.0, < 2018.3.5 | 2018.3.5 |
saltPyPI | >= 2019.2.0, < 2019.2.6 | 2019.2.6 |
saltPyPI | >= 3000.0, < 3000.4 | 3000.4 |
saltPyPI | >= 3001, < 3001.2 | 3001.2 |
saltPyPI | >= 3002, < 3002.1 | 3002.1 |
Affected products
71- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- SaltStack/SaltStack Saltdescription
- ghsa-coords63 versionspkg:pypi/saltpkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/bind-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/cobbler&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/cobbler&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/grafana-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/image-sync-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/mgr-daemon&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/mgr-daemon&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/mgr-daemon&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/prometheus-exporters-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/prometheus-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/pxe-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/py26-compat-salt&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/python-susemanager-retail&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/salt&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2012%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/salt&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/salt&distro=SUSE%20Manager%20Proxy%203.2pkg:rpm/suse/salt&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/salt-netapi-client&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/saltboot-formula&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacecmd&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/spacecmd&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-admin&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-branding&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-search&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-build-keys&distro=SUSE%20Manager%20Proxy%20Module%204.1pkg:rpm/suse/susemanager-build-keys&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-doc-indexes&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-docs_en&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-schema&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/susemanager-sls&distro=SUSE%20Manager%20Server%20Module%204.1
< 2015.8.13+ 62 more
- (no CPE)range: < 2015.8.13
- (no CPE)range: < 3000-lp151.5.30.1
- (no CPE)range: < 3000-lp152.3.15.1
- (no CPE)range: < 0.1.1603299886.60e4bcf-3.3.2
- (no CPE)range: < 2.2.2-0.68.12.1
- (no CPE)range: < 2.2.2-0.68.12.1
- (no CPE)range: < 0.3.0-3.3.2
- (no CPE)range: < 0.1.1602150122.f08af0a-3.6.2
- (no CPE)range: < 4.1.3-5.20.1
- (no CPE)range: < 4.1.3-5.20.1
- (no CPE)range: < 4.1.3-2.6.3
- (no CPE)range: < 0.8.0-3.16.2
- (no CPE)range: < 0.3.0-3.3.1
- (no CPE)range: < 0.1.1602490840.4f32148-3.3.2
- (no CPE)range: < 2016.11.10-6.41.1
- (no CPE)range: < 2016.11.10-10.17.1
- (no CPE)range: < 2016.11.10-6.3.3
- (no CPE)range: < 1.0.1602150122.f08af0a-3.3.2
- (no CPE)range: < 2016.11.4-48.13.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 3000-6.51.1
- (no CPE)range: < 3000-4.20.1
- (no CPE)range: < 3000-6.51.1
- (no CPE)range: < 3000-4.20.1
- (no CPE)range: < 3000-6.51.1
- (no CPE)range: < 3000-4.20.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 2016.11.10-43.63.1
- (no CPE)range: < 2016.11.10-43.63.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-5.91.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 3000-46.114.1
- (no CPE)range: < 0.18.0-15.7.5
- (no CPE)range: < 0.1.1602150122.f08af0a-3.6.2
- (no CPE)range: < 4.1.8-18.72.1
- (no CPE)range: < 4.1.8-18.72.1
- (no CPE)range: < 4.1.8-4.9.2
- (no CPE)range: < 4.1.8-4.9.2
- (no CPE)range: < 4.1.7-3.6.3
- (no CPE)range: < 4.1.16-4.11.5
- (no CPE)range: < 4.1.16-4.11.5
- (no CPE)range: < 4.1.11-3.9.6
- (no CPE)range: < 4.1.7-27.38.1
- (no CPE)range: < 4.1.7-27.38.1
- (no CPE)range: < 4.1.7-4.6.4
- (no CPE)range: < 4.1.7-4.6.4
- (no CPE)range: < 2.8.78.31-3.56.1
- (no CPE)range: < 4.0.39-3.45.1
- (no CPE)range: < 4.1.22-3.16.4
- (no CPE)range: < 4.1.3-3.3.7
- (no CPE)range: < 4.1.19-3.9.5
- (no CPE)range: < 4.1.19-3.9.5
- (no CPE)range: < 4.1.21-3.11.6
- (no CPE)range: < 15.2.2-3.6.3
- (no CPE)range: < 15.2.2-3.6.3
- (no CPE)range: < 4.1-11.17.1
- (no CPE)range: < 4.1-11.17.1
- (no CPE)range: < 4.1.15-3.11.2
- (no CPE)range: < 4.1.17-3.13.6
Patches
Vulnerability mechanics
References
30- packetstormsecurity.com/files/160039/SaltStack-Salt-REST-API-Arbitrary-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.htmlnvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-qr38-h96j-2j3wghsaADVISORY
- lists.debian.org/debian-lts-announce/2020/12/msg00007.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/01/msg00000.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-16846ghsaADVISORY
- security.gentoo.org/glsa/202011-13nvdThird Party AdvisoryWEB
- www.debian.org/security/2021/dsa-4837nvdMailing ListThird Party AdvisoryWEB
- www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/nvdBroken LinkVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-20-1379/nvdThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-20-1380/nvdThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-20-1381/nvdThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-20-1382/nvdThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-20-1383/nvdThird Party AdvisoryVDB Entry
- github.com/pypa/advisory-database/tree/main/vulns/salt/PYSEC-2020-104.yamlghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/2019.2.6.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3000.4.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3001.2.rstghsaWEB
- github.com/saltstack/salt/blob/8f9405cf8e6f7d7776d5000841c886dec6d96250/doc/topics/releases/3002.1.rstghsaWEB
- github.com/saltstack/salt/releasesnvdRelease NotesWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMAghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMA/nvdRelease Notes
- lists.fedoraproject.org/archives/list/[email protected]/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMAghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
- www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cvesghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1379ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1380ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1381ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1382ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-20-1383ghsaWEB
News mentions
0No linked articles in our index yet.