Skip to content

User privilege escalation

High
gdiazlo published GHSA-8w7x-52r7-qvjf Oct 9, 2023

Package

wazuh-dashboard (Wazuh)

Affected versions

= 4.4.0, 4.4.1

Patched versions

4.4.2
wazuh-kibana-app (Wazuh)
= 4.4.0, 4.4.1
4.4.2

Description

Impact

It is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not.

Patches

This has been solved in 4.4.2

Workarounds

There are no workarounds.

References

Severity

High
8.8
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE ID

CVE-2023-42455

Weaknesses

No CWEs