Threat intelligence report · CISA KEV

CVE-2020-16846: SaltStack Salt Shell Injection Vulnerability

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. Required action: Apply updates per vendor instructions.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2021-11-03T00:00:00Z
Confidence basis
No actor match
Record ID
5d763ab857ab55763cce

Vulnerabilities

CVE-2020-16846

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.