SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
"https://github.com/pypa/advisory-database/blob/main/vulns/salt/PYSEC-2018-30.yaml"