CNNVD-202510-3969 Information
Oct 29, 2025
cve
CNNVD ID
CNNVD-202510-3969
Related CVE
- CNNVD Published: 2025-10-29
Description (Chinese)
Wazuh是Wazuh开源的一个应用软件。用于收集,汇总,索引和分析安全数据,帮助组织检测入侵,威胁和行为异常。 Wazuh 4.12.0之前版本存在安全漏洞,该漏洞源于w_expression_match函数中未正确终止缓冲区,可能导致缓冲区过度读取和敏感数据泄露。
Description (English)
Wazuh is an application from the Wazuh Open Source. For collection, aggregation, indexing and analysis of security data to help the organization detect invasions, threats and behavioural anomalies. There was a security loophole in the pre-Wazuh 4.12.0 version, which stemmed from the incorrect termination of the buffer zone in the w expresion metch function, which could lead to overreading and sensitive data leaking in the buffer zone.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Wazuh
Published
2025-10-29
Last Modified
2026-02-24
References
https://github.com/wazuh/wazuh/security/advisories/GHSA-2672-vfhm-xhr6 https://access.redhat.com/security/cve/cve-2025-62792