Related Vulnerabilities: CVE-2020-16846  

An issue has been found in Salt before 3001.3, 3000.5, 2019.2.7 where an unauthenticated user with network access to the Salt API can use shell injections to run code on the Salt API using the SSH client.

Severity High

Remote Yes

Type Arbitrary command execution

Description

An issue has been found in Salt before 3001.3, 3000.5, 2019.2.7 where an unauthenticated user with network access to the Salt API can use shell injections to run code on the Salt API using the SSH client.

AVG-1262 salt 2019.2.4-1 2019.2.7-1 Critical Fixed

10 Nov 2020 ASA-202011-7 AVG-1262 salt Critical multiple issues

https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/
https://gitlab.com/saltstack/open/salt-patches/-/blob/master/patches/2020/09/02/2019.2.x.patch