The salt-master process ClearFuncs class does not properly validate method calls.
This allows a remote user to access some methods without authentication.
These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.