Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2pm-mgrm-39hq

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager's admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

nvd
2 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.

CVSS3: 10
fstec
4 месяца назад

Уязвимость функции inventory_sync() компонента синхронизации кластера Wazuh Manager платформы для мониторинга безопасности и обнаружения угроз Wazuh, позволяющая нарушителю выполнить произвольный код

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-74