Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI KEV

SaltStack Salt Command Injection in netapi ssh client

GHSA-qr38-h96j-2j3w · CVE-2020-16846 · PYSEC-2020-104

Published · Modified

Description

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes