The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
"https://github.com/pypa/advisory-database/blob/main/vulns/salt/PYSEC-2013-15.yaml"