A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. The Salt-API’s SSH client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
A security issue was found in SaltStack before versions 3002.5, 3001.6 and 3000.8. The Salt-API’s SSH client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/