
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2023-50260) affects Wazuh's active response feature, specifically in versions 4.2.0 through 4.7.1. Discovered by a researcher working with Trend Micro Zero Day Initiative, this vulnerability was disclosed and patched in April 2024. The flaw exists within the host_deny script, which is part of Wazuh's active response mechanism that automatically triggers actions in response to alerts (Wazuh Advisory).
The vulnerability stems from improper validation of JSON messages, specifically in the handling of IP address arguments within the host_deny script. The issue allows writing arbitrary strings to the hosts.deny file, which can lead to command execution. The vulnerability has been assigned a CVSS score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating its high severity. The flaw is classified as CWE-94, relating to improper control of generation of code (ZDI Advisory, Wazuh Advisory).
The vulnerability can result in system compromise, allowing remote attackers to gain control of vulnerable systems. When successfully exploited, it can lead to arbitrary command execution in the context of root, potentially affecting both server and agent hosts. The impact is particularly severe as it can lead to Local Privilege Escalation (LPE) on the server as root and Remote Code Execution (RCE) on agents as root (Fortiguard, Wazuh Advisory).
The vulnerability requires authentication to exploit. An attacker can trigger the active response by writing events either to the local execd queue on the server or to the ar queue which forwards the events to agents. The exploitation involves crafting specific JSON messages that can bypass the input validation mechanisms (ZDI Advisory, Wazuh Advisory).
Wazuh has released version 4.7.2 to address this vulnerability. Organizations running affected versions (4.2.0 through 4.7.1) should upgrade to version 4.7.2 or later to mitigate the risk (Wazuh Advisory, Fortiguard).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."