Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2pm-mgrm-39hq

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

EPSS

Процентиль: 28%
0.00351
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 10
nvd
18 дней назад

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

CVSS3: 10
fstec
около 2 месяцев назад

Уязвимость функции inventory_sync() компонента синхронизации кластера Wazuh Manager платформы для мониторинга безопасности и обнаружения угроз Wazuh, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 28%
0.00351
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-74