CVE-2020-28972 log

Source
Severity High
Remote Yes
Type Certificate verification bypass
Description
In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.
Group Package Affected Fixed Severity Status Ticket
AVG-1624 salt 2019.2.7-1 3002.5-3 High Fixed
Date Advisory Group Package Severity Type
27 Feb 2021 ASA-202102-33 AVG-1624 salt High multiple issues
References
https://saltproject.io/security_announcements/active-saltstack-cve-release-2021-feb-25/