.. / CVE-2020-16846

Exploit for SaltStack <=3002 - Shell Injection (CVE-2020-16846)

Description:

SaltStack Salt through 3002 allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt-API using the SSH client.

Nuclei Template

View the template here CVE-2020-16846.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-16846.yaml
Copy

References:

https://saltproject.io/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00029.html
https://mp.weixin.qq.com/s/R8qw_lWizGyeJS0jOcYXag
https://github.com/vulhub/vulhub/tree/master/saltstack/CVE-2020-16846
https://nvd.nist.gov/vuln/detail/CVE-2020-16846