An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.
2025-06-13T07:15:21.010
2025-06-16T12:32:18.840
Awaiting Analysis
CVSSv3.1: 6.7 (MEDIUM)
-