Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v276-37m6-wc5x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the wazuh-slack active response script in Wazuh before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.

In the wazuh-slack active response script in Wazuh before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.

EPSS

Процентиль: 92%
0.08313
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.

EPSS

Процентиль: 92%
0.08313
Низкий

Дефекты

CWE-77