An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Salt | Saltstack | * | 3000.3 (excluding) |
Salt | Ubuntu | bionic | * |
Salt | Ubuntu | hirsute | * |
Salt | Ubuntu | impish | * |
Salt | Ubuntu | kinetic | * |
Salt | Ubuntu | trusty | * |
Salt | Ubuntu | trusty/esm | * |
Salt | Ubuntu | xenial | * |