Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.
| Software | From | Fixed in |
|---|---|---|
| saltstack / salt | 0.17.0 | 0.17.0.x |
| saltstack / salt | 0.16.3 | 0.16.3.x |
| saltstack / salt | 0.15.1 | 0.15.1.x |
| saltstack / salt | 0.16.2 | 0.16.2.x |
| saltstack / salt | 0.16.4 | 0.16.4.x |
| saltstack / salt | 0.15.0 | 0.15.0.x |
| saltstack / salt | 0.16.0 | 0.16.0.x |