PyPI package intelligence

salt Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the PyPI package salt, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
3
Known exploited vulnerabilities affecting salt
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
salt KEVs with sensor-observed exploitation activity

Review salt exploitation against the versions you run

All three exploited salt vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested salt vulnerabilities

3 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2020-16846

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in...

In CISA 03 Nov 2021
CVE-2020-11651

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly...

In CISA 03 Nov 2021
CVE-2020-11652

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some...

In CISA 03 Nov 2021

Recurring weakness patterns

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') account for mapped occurrences across this salt KEV portfolio.

Browse all KEVs →