FlawAtlas
Search the atlas
CVE-2024-47770 Moderate

Ability to view Agent list with no privilege access in wazuh-dashboard in github.com/wazuh/wazuh

Ability to view Agent list with no privilege access in wazuh-dashboard in github.com/wazuh/wazuh

Exploit probability 0.2%
Published February 4, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

11 explicit affected versions

Go github.com/wazuh/wazuh

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-47770

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. This vulnerability occurs when the system has weak privilege access, that allows an attacker to do privilege escalation. In this case the attacker is able to view agent list on Wazuh dashboard with no privilege access. This issue has been addressed in release version 4.9.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

View original source
Open Source Vulnerabilities GO-2025-3445

Ability to view Agent list with no privilege access in wazuh-dashboard in github.com/wazuh/wazuh

View original source

05 / REFERENCES

Further evidence