OS Command Injection in Salt - CVE-2020-16846
Published: November 6, 2020 / Updated: December 12, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in SaltStack Salt when processing API requests. A remote attacker can send specially crafted request to the server and execute arbitrary OS commands on the target system.
Successful exploitation of the vulnerability requires that SSH client is enabled.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
Opensuse
Fedora
salt (Alpine package)
salt (Debian package)
salt-common (Ubuntu package)
salt-minion (Ubuntu package)
salt
How to mitigate CVE-2020-16846
salt (Alpine package) - update to 3002-r1
salt (Debian package) - update to 2018.3.4+dfsg1-6+deb10u2
salt-common (Ubuntu package) - addressed in versions Ubuntu Pro, salt-master
salt-minion (Ubuntu package) - update to salt-ssh
salt - addressed in versions 3001.3-1.fc31, 3001.3-1.fc32, 3002.1-1.fc33
Links to Public Exploits and PoC-codes
External References
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html
- https://github.com/saltstack/salt/releases
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TPOGB2F6XUAIGFDTOCQDNB2VIXFXHWMA/
- https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/
Related Security Bulletins
- Multiple vulnerabilities in SaltStack Salt
- OpenSUSE Linux update for salt
- OpenSUSE Linux update for salt
- Arch Linux update for salt
- OS Command Injection in salt (Alpine package)
- Gentoo update for Salt
- Debian update for salt
- Ubuntu update for salt
- Ubuntu update for salt
- Fedora 31 update for salt
- Fedora 32 update for salt
- Fedora 33 update for salt