漏洞标题
N/A
漏洞描述信息
Wazuh SIEM 4.8.2版本存在访问控制失效漏洞。该漏洞允许未经授权的内部用户创建,且无需分配任何现有用户角色,可能导致权限提升或未经授权访问敏感资源。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
特权管理不恰当
漏洞标题
N/A
漏洞描述信息
Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.
CVSS信息
N/A
漏洞类别
N/A