PyPI package intelligence
salt Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the PyPI package salt, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting salt
- In CISA KEV
- 3
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- salt KEVs with sensor-observed exploitation activity
Review salt exploitation against the versions you run
All three exploited salt vulnerabilities tracked here are also listed in CISA KEV.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
Attested salt vulnerabilities
3 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2020-16846
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in... |
In CISA | 03 Nov 2021 |
|
CVE-2020-11651
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly... |
In CISA | 03 Nov 2021 |
|
CVE-2020-11652
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some... |
In CISA | 03 Nov 2021 |
Recurring weakness patterns
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') account for mapped occurrences across this salt KEV portfolio.