CVE-2020-16846
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
99.6%
99.9th percentile
CISA KEV
Listed
Added 2021-11-03 · patch by 2022-05-03
Weakness / dates
—
Published — · modified —
Description
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.