claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2020-16846-saltstack-salt.log

CVE-2020-16846 — SaltStack Salt Shell Injection Vulnerability

2021-11-03 • CISA Known Exploited Vulnerability


[event] SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

> AFFECTED SOFTWARE

Field Value
Vendor SaltStack
Product Salt
CWE CWE-78
CVE ID CVE-2020-16846
Date Added 2021-11-03
Due Date 2022-05-03
Ransomware Campaign Unknown

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2022-05-03

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:16 UTC