An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Salt | Saltstack | * | 3000.3 (excluding) | 
| Salt | Ubuntu | bionic | * | 
| Salt | Ubuntu | hirsute | * | 
| Salt | Ubuntu | impish | * | 
| Salt | Ubuntu | kinetic | * | 
| Salt | Ubuntu | trusty | * | 
| Salt | Ubuntu | trusty/esm | * | 
| Salt | Ubuntu | xenial | * |