Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-42455: User privilege escalation

Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not. Version 4.4.2 contains a fix. There are no known workarounds.

CVE

High

gdiazlo published GHSA-8w7x-52r7-qvjf

Oct 9, 2023

Package

wazuh-dashboard (Wazuh)

Affected versions

= 4.4.0, 4.4.1

Description

Impact

It is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not.

Patches

This has been solved in 4.4.2

Workarounds

There are no workarounds.

References

  • #5428

Severity

CVSS base metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907