The host is installed with SaltStack Salt before 3002.9 or 3003 before 3003.5 or 3004 before 3004.2 and is prone to an incorrect authorization vulnerability. A flaw exists exists within the application, which fails to properly handle the PAM auth. Successful exploitation allows a previously authorized user whose account is locked still run Salt commands when their account is locked affecting both ...