The Salt-API’s SSH client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request. References: https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/
Created salt tracking bugs for this issue: Affects: fedora-all [bug 1933324]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-3197
Statement: Salt has been deprecated as of Red Hat Ceph Storage 2.5, as Salt was used to install RHSCON-2 and RHSCON-2 has reached End Of Life.