Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-44079

In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.083
EPSS Ranking 91.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-44079
  • Wazuh » Wazuh » Version: 4.2.0
    cpe:2.3:a:wazuh:wazuh:4.2.0
  • Wazuh » Wazuh » Version: 4.2.1
    cpe:2.3:a:wazuh:wazuh:4.2.1
  • Wazuh » Wazuh » Version: 4.2.2
    cpe:2.3:a:wazuh:wazuh:4.2.2
  • Wazuh » Wazuh » Version: 4.2.3
    cpe:2.3:a:wazuh:wazuh:4.2.3
  • Wazuh » Wazuh » Version: 4.2.4
    cpe:2.3:a:wazuh:wazuh:4.2.4


Contact Us

Shodan ® - All rights reserved