CVE-2025-15612

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-27 19:16

Updated : 2026-03-30 13:26


NVD link : CVE-2025-15612

Mitre link : CVE-2025-15612

CVE.ORG link : CVE-2025-15612


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation

CWE-829

Inclusion of Functionality from Untrusted Control Sphere