CVE-2023-42455 - CVE House
Back to Database
Status published High CVE-2023-42455

Wazuh vulnerable to user privilege escalation

Vulnerability Description

Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their dashboard role is not. Version 4.4.2 contains a fix. There are no known workarounds.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-42455

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

wazuh-kibana-app
Vulnerable Versions:
>= 4.4.0, < 4.4.2

Timeline

Official Publish: October 9th, 2023
Last Modified: September 19th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)