Exposure Vulnerability in Wazuh by Wazuh Inc.
CVE-2025-15617
6.3MEDIUM
What is CVE-2025-15617?
Wazuh version 4.12.0 contains a significant exposure vulnerability within its GitHub Actions workflow. This flaw allows malicious actors to access sensitive GITHUB_TOKEN stored in uploaded artifacts. Once the token is retrieved, attackers could misuse it within a restricted timeframe to carry out unauthorized actions, such as pushing harmful commits or modifying release tags, thus compromising the integrity of the repository and associated projects.
Affected Version(s)
Wazuh (GitHub Actions) 4.12.0
