Code base not validating SSL/TLS certificate of the server, which might allow attackers to obtain sensitive information via a man-in-the-middle attack. References: https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/
Created salt tracking bugs for this issue: Affects: fedora-all [bug 1933348]
External References: https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-28972