CVE-2025-15617
⚪ Do wiadomości
Wykrycie w Wazuh 4.12.0 pozwala na wyciek GITHUB_TOKEN, co umożliwia nieautoryzowane działania.
CVSS
6.5
EPSS
0.4%
Exploit
poc
Vendor
wazuh
Opis źródłowy (NVD)
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-03-27 18:16:03 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 09:10:00 UTC |
Referencje
- https://github.com/wazuh/wazuh/security/advisories/GHSA-6xqr-4q5g-xc7x ([email protected]) [Exploit, Vendor Advisory]
- https://www.vulncheck.com/advisories/exposure-of-the-github-token-in-wazuh-workflow-run-artifact ([email protected]) [Third Party Advisory]