#VU58293 Improper Authentication in Salt - CVE-2021-22004
Published: November 23, 2021
Salt
SaltStack
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to the salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. A local user with ability to create files in the said directory can subvert the proper behavior of the given minion software.