Description
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
Problem types
CWE-295 Improper Certificate Validation
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Product status
>=4.1.3 (custom)
>=4.14.0 (custom)
Credits
JLLeitschuh
vikman90
References
github.com/.../wazuh/security/advisories/GHSA-wvg9-7q49-c7mg
www.vulncheck.com/...ing-to-mitm-rce-in-build-infrastructure