CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-16846

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score40.6510%
EPSS Percentile96.69th
Published2020-11-06
Last Modified2025-11-07
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

Affected Platforms (CPE)

📦
Saltstack

Salt

< 2015.8.10>= 2015.8.11 and < 2015.8.13>= 2016.3.0 and < 2016.3.4>= 2016.3.5 and < 2016.3.6>= 2016.3.7 and < 2016.3.8>= 2016.11.0 and < 2016.11.3>= 2016.11.4 and < 2016.11.6>= 2016.11.7 and < 2016.11.10>= 2017.5.0 and < 2017.7.4>= 2017.7.5 and < 2017.7.8>= 2018.2.0 and < 2018.3.5>= 2019.2.0 and < 2019.2.5>= 3000.0 and < 3000.3= 3001= 3002
💻
Debian

Debian Linux

= 9.0= 10.0
💻
Fedoraproject

Fedora

= 31
💻
Opensuse

Leap

= 15.1

References & Advisories

相關漏洞威脅