Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp7g-9j3h-9mcg

Опубликовано: 27 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 4.8

Описание

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

EPSS

Процентиль: 12%
0.00216
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 4.8
nvd
5 месяцев назад

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

CVSS3: 4.8
fstec
8 месяцев назад

Уязвимость системы обнаружения и предотвращения вторжений Wazuh, связанная с неправильным подтверждением подлинности сертификата, позволяющая нарушителю выполнить атаку типа «человек посередине» (MITM) и выполнить произвольный код

EPSS

Процентиль: 12%
0.00216
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-295