F-Secure disclosed a number of vulnerabilities in the Salt framework, including two issues that have been exploited by attackers to take over Salt installations. The two flaws are a directory traversal issue and an authentication bypass vulnerability respectively. Chaining the issue, an attacker could bypass authentication and run arbitrary code on Salt master servers exposed online. Several organizations disclosed data breaches that involved exploitation of the above flaws, including LineageOS, Ghost, and DigiCert. The virtualization giant has provided workarounds to mitigate the issues.”]
Source: https://securityaffairs.co/wordpress/103063/security/vmware-salt-issues-vrops.html

