CVE-2025-15612
EUVD-2025-20910727.03.2026, 19:16
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wazuh | wazuh | 4.1.3 ≤ 𝑥 < 4.14.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration