{
  "threat_severity" : "Important",
  "public_date" : "2020-11-03T00:00:00Z",
  "bugzilla" : {
    "description" : "salt: sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection",
    "id" : "1895449",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1895449"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-78",
  "details" : [ "An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.", "A flaw was found in salt. A shell injection vulnerability was found where an unauthenticated user with network access to the Salt API can use shell injections to run code on the Salt-API using the SSH client. An attacker could use this flaw to cause a denial of service, information disclosure, or privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability." ],
  "statement" : "Red Hat Ceph Storage 2 shipped salt for the usage of Red Hat Storage Console 2 (RHSCON-2), which required salt to administrate ceph nodes. RHSCON-2 has reached End Of Life, hence salt is no longer used and supported. Therefore, the salt package provided by Red Hat Ceph Storage 2 has been marked as 'will not fix'.",
  "package_state" : [ {
    "product_name" : "Red Hat Ceph Storage 2",
    "fix_state" : "Will not fix",
    "package_name" : "salt",
    "cpe" : "cpe:/a:redhat:ceph_storage:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-16846\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-16846\nhttps://docs.saltstack.com/en/latest/topics/releases/2019.2.6.html\nhttps://docs.saltstack.com/en/latest/topics/releases/3000.4.html\nhttps://docs.saltstack.com/en/latest/topics/releases/3001.2.html\nhttps://docs.saltstack.com/en/latest/topics/releases/3002.1.html\nhttps://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/\nhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog" ],
  "name" : "CVE-2020-16846",
  "mitigation" : {
    "value" : "Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.",
    "lang" : "en:us"
  },
  "csaw" : false
}