← Browse

CVE-2020-16846

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
99.6%
99.9th percentile
CISA KEV
Listed
Added 2021-11-03 · patch by 2022-05-03
Weakness / dates
Published — · modified —

Timeline

Description

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

Official: NVD · CVE.org