Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Exposure of Resource to Wrong Sphere in salt

GHSA-pf7h-h2wq-m7pg · CVE-2021-21996 · PYSEC-2021-318

Published · Modified

Description

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

Ready to move

Start Securing

Free, no credit card | First findings in minutes