Log Processing Vulnerability in OSSEC-HIDS by Open Source Security Inc.
CVE-2020-8445
9.8CRITICAL
What is CVE-2020-8445?
In OSSEC-HIDS versions 2.7 to 3.5.0, a flaw in the OS_CleanMSG function of the ossec-analysisd component fails to properly remove or encode terminal control characters and newlines from log messages. As a result, it can lead to nested event injections within the OSSEC log. This vulnerability permits the use of these characters for potentially obfuscating logged events or executing arbitrary commands when viewed through affected terminal emulators. Additionally, it can be exploited via unauthenticated remote attacks depending on the data origin and type.
