CVE-2021-26814

Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service script.
References
Link Resource
https://documentation.wazuh.com/4.0/release-notes/release_4_0_4.html Release Notes Vendor Advisory
https://github.com/wazuh/wazuh/releases/tag/v4.0.4 Release Notes Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-20 CWE-22

11 Mar 2021, 21:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CWE CWE-20
CPE cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*:*
References (MISC) https://github.com/wazuh/wazuh/releases/tag/v4.0.4 - (MISC) https://github.com/wazuh/wazuh/releases/tag/v4.0.4 - Release Notes, Third Party Advisory
References (MISC) https://documentation.wazuh.com/4.0/release-notes/release_4_0_4.html - (MISC) https://documentation.wazuh.com/4.0/release-notes/release_4_0_4.html - Release Notes, Vendor Advisory

06 Mar 2021, 03:09

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-06 02:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-26814

Mitre link : CVE-2021-26814

CVE.ORG link : CVE-2021-26814


JSON object : View

Products Affected

wazuh

  • wazuh
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')