Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Wazuh 命令注入漏洞
Vulnerability Description
Wazuh是 (Wazuh)开源的一个应用软件。用于收集,汇总,索引和分析安全数据,帮助组织检测入侵,威胁和行为异常。 Wazuh 4.2.5 之前的 wazuh-slack 主动响应脚本中存在命令注入漏洞,该漏洞源于不受信任的用户代理被传递到 curl 命令行,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A