Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-27 19:16
Updated : 2026-03-30 13:26
NVD link : CVE-2025-15612
Mitre link : CVE-2025-15612
CVE.ORG link : CVE-2025-15612
JSON object : View
Products Affected
No product.
