Executive brief
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
Affected products
- PyPI salt
Junglewise Threat Intelligence
CVE-2021-21996 · Severity: low · CVSS 3.1 · Published 2021-09-08
Technologies: salt (PyPI). Vendors: PyPI.
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.