VDB
KO

PYSEC-2021-346

Details

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / salt
Introduced in: 0 Fixed in: 3003.3
Fix pip install --upgrade 'salt>=3003.3'

References