Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster…
高危 CVSS 7.2
摘要
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside WAZUH_PATH. A syn_i_w_m_e request with an unknown task_id reaches the cleanup branch, where an attacker-controlled filename is passed to os.path.join without canonicalization or confinement. Absolute paths and traversal sequences…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/wazuh/wazuh/commit/90d43547d166cdbe65e9a3d011f946214df9179c Patch
- https://github.com/wazuh/wazuh/pull/36060 Issue Tracking
- https://github.com/wazuh/wazuh/releases/tag/v4.14.6 Patch
- https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2 Patch
- https://github.com/wazuh/wazuh/security/advisories/GHSA-cqvw-w2rg-327f Exploit
- https://github.com/wazuh/wazuh/security/advisories/GHSA-cqvw-w2rg-327f Exploit
时间线
- nvd_ingest NVD