MEDIUM 6.4 PyPI

Improper Authentication in SaltStack Salt

GHSA-xf37-qcvf-7m57 · CVE-2021-22004 · PYSEC-2021-346

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

Ready to move

Start Securing

Free, no credit card | First findings in minutes