CVE-2020-25592


A vulnerability was found in SaltStack Salt up to 3002 and classified as critical. Affected by this issue is an unknown function of the component salt-netapi. The manipulation with an unknown input leads to a improper authentication vulnerability. Using CWE to declare the problem leads to CWE-287. When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. Impacted is confidentiality, integrity, and availability.

Exploit


Referring to the article found online