Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster…
High CVSS 7.2
Summary
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside WAZUH_PATH. A syn_i_w_m_e request with an unknown task_id reaches the cleanup branch, where an attacker-controlled filename is passed to os.path.join without canonicalization or confinement. Absolute paths and traversal sequences…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/wazuh/wazuh/commit/90d43547d166cdbe65e9a3d011f946214df9179c Patch
- https://github.com/wazuh/wazuh/pull/36060 Issue Tracking
- https://github.com/wazuh/wazuh/releases/tag/v4.14.6 Patch
- https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2 Patch
- https://github.com/wazuh/wazuh/security/advisories/GHSA-cqvw-w2rg-327f Exploit
- https://github.com/wazuh/wazuh/security/advisories/GHSA-cqvw-w2rg-327f Exploit
Timeline
- nvd_ingest NVD