FlawAtlas
Search the atlas
CVE-2020-16846 Critical

Confirmed as exploited

CVE-2020-16846

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

Exploit probability 99.6%
Published November 6, 2020
Required by May 3, 2022
Last source change June 10, 2026

01 / ACTION

Required action

Apply updates per vendor instructions.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

89 explicit affected versions

PyPI salt

144 explicit affected versions

PyPI salt

156 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2020-16846

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

View original source
Open Source Vulnerabilities CVE-2020-16846

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

View original source
Open Source Vulnerabilities PYSEC-2020-104

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

View original source
Open Source Vulnerabilities GHSA-qr38-h96j-2j3w

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

View original source

05 / REFERENCES

Further evidence