CVE-2020-16846
Description
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.387
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2020-16846 are affected in Salt 3001 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.11.2 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.11.5 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.3.7 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2015.8.12 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.3.3 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.3.5 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2017.7.7 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2015.8.9 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2016.11.9 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 2017.7.3 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 2018.3.4 | Windows |
| Multiple Vulnerabilities are affected in VMware SALT 2019.2.4 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 3000.2 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 3001 | Windows |
| Multiple vulnerabilities are fixed in Python-salt 2016.3.8 | Windows |
| Multiple vulnerabilities are fixed in Python-salt 2015.8.13 | Windows |
| Multiple vulnerabilities are fixed in Python-salt 2016.11.10 | Windows |
| Multiple vulnerabilities are fixed in Python-salt 2017.7.8 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt 2018.3.5 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490 are fixed in Python-salt 2019.2.6 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490 are fixed in Python-salt 3000.4 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490 are fixed in Python-salt 3001.2 | Windows |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt 3002.1 | Windows |
| Multiple vulnerabilities are fixed in Python-salt for linux 2016.3.8 | Linux |
| Multiple vulnerabilities are fixed in Python-salt for linux 2015.8.13 | Linux |
| Multiple vulnerabilities are fixed in Python-salt for linux 2016.11.10 | Linux |
| Multiple vulnerabilities are fixed in Python-salt for linux 2017.7.8 | Linux |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt for linux 2018.3.5 | Linux |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490 are fixed in Python-salt for linux 2019.2.6 | Linux |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490 are fixed in Python-salt for linux 3000.4 | Linux |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490 are fixed in Python-salt for linux 3001.2 | Linux |
| Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt for linux 3002.1 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234