Wazuh
cpe:2.3:a:wazuh:wazuh:*:*:*:*:*:*:*
- >= 4.6.0
A logic error has been identified in Wazuh versions 4.6.0 and above, prior to 4.14.5. The issue resides in the CheckRateLimitsMiddleware.dispatch() function, where the /events endpoint's rate check improperly overrides the general rate limit. As a result, when the global max_request_per_minute limit is surpassed, requests to /events can still be processed if the events-specific limit of 30 requests per minute has not been reached. This flaw enables event injection into analysisd, bypassing the globally configured rate limits.
Exploitation of this vulnerability allows for event injection into the analysisd component, exceeding the administrator-defined global rate limits.
Users can upgrade to Wazuh version 4.14.5 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.