CVE-2020-16846: SaltStack Salt Shell Injection Vulnerability
A user could use shell injections with the Salt API using the SSH Client.
Other sources
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
— Launchpad
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3002.1 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3001.2 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 3000.4 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2019.2.6 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2018.3.5 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2017.7.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.11.10 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2016.3.8 - Upgrade
Upgrade
pip/saltto a version that resolves this vulnerability.Fixed in 2015.8.13 - Upgrade
Upgrade
SaltStackto a version that resolves this vulnerability.Fixed in 3002Fixed in 3001.1, 3001.2Fixed in 3000.3, 3000.4Fixed in 2019.2.5, 2019.2.6Fixed in 2018.3.5Fixed in 2017.7.4, 2017.7.8Fixed in 2016.11.3, 2016.11.6, 2016.11.10Fixed in 2016.3.4, 2016.3.6, 2016.3.8Fixed in 2015.8.10, 2015.8.13Fixed in 3002.xFixed in 3001.xFixed in 3000.xFixed in 2019.x
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-16846?
CVE-2020-16846 is a SaltStack Salt Shell Injection Vulnerability.
How severe is CVE-2020-16846?
CVE-2020-16846 has a severity rating of 9.8 (critical).
What software is affected by CVE-2020-16846?
CVE-2020-16846 affects installations of SaltStack Salt versions 2018.3.4+dfsg1-6+deb10u3, 3002.6+dfsg1-4+deb11u1, and 3004.1+dfsg-2.2.
Is authentication required to exploit CVE-2020-16846?
No, authentication is not required to exploit CVE-2020-16846.
How can I fix CVE-2020-16846?
To fix CVE-2020-16846, it is recommended to update to a patched version of SaltStack Salt.