SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-42455

This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not.

HIGH 8.8EPSS 0.59%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not. Version 4.4.2 contains a fix. There are no known workarounds.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.59% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-639
Affected
wazuh/wazuh-dashboard · wazuh/wazuh-kibana-app
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.