Описание
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags.
Ссылки
- ExploitVendor Advisory
- Third Party Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
EPSS
6.5 Medium
CVSS3
8.1 High
CVSS3
Дефекты
Связанные уязвимости
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags.
Уязвимость конфигурационного файла 4_testintegration_fim-tier-0-1-win.yml платформы для мониторинга безопасности и обнаружения угроз Wazuh, позволяющая нарушителю получить доступ на чтение и изменение данных
EPSS
6.5 Medium
CVSS3
8.1 High
CVSS3