Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2025-15612

5 месяцев назад

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-wp7g-9j3h-9mcg

5 месяцев назад

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

CVSS3: 4.8
EPSS: Низкий
fstec логотип

BDU:2026-04705

8 месяцев назад

Уязвимость системы обнаружения и предотвращения вторжений Wazuh, связанная с неправильным подтверждением подлинности сертификата, позволяющая нарушителю выполнить атаку типа «человек посередине» (MITM) и выполнить произвольный код

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-15612

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

CVSS3: 4.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-wp7g-9j3h-9mcg

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

CVSS3: 4.8
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-04705

Уязвимость системы обнаружения и предотвращения вторжений Wazuh, связанная с неправильным подтверждением подлинности сертификата, позволяющая нарушителю выполнить атаку типа «человек посередине» (MITM) и выполнить произвольный код

CVSS3: 4.8
0%
Низкий
8 месяцев назад

Уязвимостей на страницу