Related Vulnerabilities: CVE-2021-25282  

A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. Unauthorized access to wheel_async through the salt-api can execute arbitrary code/commands.

Severity Medium

Remote Yes

Type Directory traversal

Description

A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. Unauthorized access to wheel_async through the salt-api can execute arbitrary code/commands.

AVG-1624 salt 2019.2.7-1 High Vulnerable

https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/