#VU50979 Improper access control in Salt - CVE-2021-25281
Published: February 28, 2021 / Updated: May 9, 2021
Salt
SaltStack
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. The salt-api does not honor eauth credentials for the wheel_async client. A remote attacker can remotely run any wheel modules on the master.