CVE Vulnerabilities

CVE-2022-41918

Improper Authorization of Index Containing Sensitive Information

Published: Nov 15, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to update. There are no known workarounds for this issue.

Weakness

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Affected Software

Name Vendor Start Version End Version
Opensearch Amazon * 1.3.7 (excluding)
Opensearch Amazon 2.0.0 (including) 2.4.0 (excluding)

References