Related Vulnerabilities: CVE-2021-22004  

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

Severity Medium

Remote No

Type Insufficient validation

Description

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

AVG-2356 salt 3003.2-1 3003.3-1 Medium Not affected

https://saltproject.io/security_announcements/salt-security-advisory-2021-sep-02/