A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. A privilege escalation is possible on a SaltStack minion when an unprivileged user is able to create files in any non-blacklisted directory via a command injection in a process name.
A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. A privilege escalation is possible on a SaltStack minion when an unprivileged user is able to create files in any non-blacklisted directory via a command injection in a process name.
https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/