PT-2021-17147 · Wazuh · Wazuh

Davide Meacci

·

Published

2021-03-06

·

Updated

2022-07-12

·

CVE-2021-26814

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wazuh versions 4.0.0 through 4.0.3
Description: The issue allows authenticated users to execute arbitrary code with administrative privileges via the "/manager/files" API endpoint. This is possible due to incomplete input validation on the "/manager/files" API, which can be exploited by an authenticated user to inject arbitrary code within the API service script.
Recommendations: For versions 4.0.0 through 4.0.3, update to a version outside of this range to mitigate the risk of arbitrary code execution. As a temporary workaround, consider restricting access to the "/manager/files" API endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26814
GHSA-W36G-Q975-37RG

Affected Products

Wazuh