CVE-2023-42455
This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not. Version 4.4.2 contains a fix. There are no known workarounds.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- wazuh/wazuh-dashboard · wazuh/wazuh-kibana-app
- Source
- security-advisories@github.com
References
- https://github.com/wazuh/wazuh-dashboard-plugins/issues/5427Issue Tracking
- https://github.com/wazuh/wazuh-kibana-app/pull/5428Patch
- https://github.com/wazuh/wazuh-kibana-app/security/advisories/GHSA-8w7x-52r7-qvjfPatch, Vendor Advisory
- https://github.com/wazuh/wazuh-dashboard-plugins/issues/5427Issue Tracking
- https://github.com/wazuh/wazuh-kibana-app/pull/5428Patch
- https://github.com/wazuh/wazuh-kibana-app/security/advisories/GHSA-8w7x-52r7-qvjfPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.