Executive brief
Wazuh is a security monitoring and threat detection platform used by organizations to protect their IT infrastructure. An authenticated user can exploit incomplete input validation in the API's file management endpoint to inject and execute arbitrary code with administrative privileges, compromising the entire monitoring system and its protected assets.
Technical details
The vulnerability is an improper input validation flaw (CWE-20) in the Wazuh API's /manager/files and /cluster/{node_id}/files endpoints. An authenticated attacker can exploit incomplete validation to inject arbitrary code that executes within the API service process. The attack requires valid API credentials and network access to the API endpoint. Successful exploitation allows remote code execution with administrative privileges, enabling complete system compromise. The vulnerability affects versions 4.0.0 through 4.0.3 and was fixed in version 4.0.4.
Affected products
- Wazuh Wazuh 4.0.0 to 4.0.3
Timeline
- 2021-03-06: disclosed: NVD publication date
- 2021-03-18: advisory: GitHub advisory GHSA-w36g-q975-37rg published
- 2021-03-18: patched: Fix released in version 4.0.4