A privilege escalation is possible on a SaltStack minion when an unprivileged user is able to create files in any non-blacklisted directory via a command injection in a process name.
Created salt tracking bugs for this issue:
Affects: fedora-all [bug 1933351]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
Salt has been deprecated as of Red Hat Ceph Storage 2.5, as Salt was used to install RHSCON-2 and RHSCON-2 has reached End Of Life.