Related Vulnerabilities: CVE-2020-28972  

A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. The code base was not validating the SSL/TLS certificate of the server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

Severity High

Remote Yes

Type Certificate verification bypass

Description

A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. The code base was not validating the SSL/TLS certificate of the server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack.

AVG-1624 salt 2019.2.7-1 High Vulnerable

https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/