<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenSearch</title>
  <link>https://cvedaily.com/pages/tags/opensearch.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/opensearch.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenSearch</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-43826 – The OpenSearch logging provider, when configured with a `host` URL that embeds c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43826</guid>
    <pubDate>Mon, 11 May 2026 09:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43826</strong></p>
  <p>The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to `apache-airflow-providers-opensearch` 1.9.1 or later and…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7191 – Improper use of the static-eval npm package in the open source solution qnabot-o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7191</guid>
    <pubDate>Mon, 27 Apr 2026 21:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7191</strong></p>
  <p>Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content Designer interface, which bypasses the intended expression sandbox through JavaScript prototype mani…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9624 – A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9624</guid>
    <pubDate>Tue, 25 Nov 2025 20:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9624</strong></p>
  <p>A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.    This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53059 – Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53059</guid>
    <pubDate>Tue, 21 Oct 2025 20:20:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53059</strong></p>
  <p>Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized ac…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62371 – OpenSearch Data Prepper as an open source data collector for observability data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62371</guid>
    <pubDate>Wed, 15 Oct 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62371</strong></p>
  <p>OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically use a trust all SSL strategy when connecting to OpenSearch clusters if no certif…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-54160 – dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in Ope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54160</guid>
    <pubDate>Wed, 12 Feb 2025 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-54160</strong></p>
  <p>dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23671 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23671</guid>
    <pubDate>Fri, 31 Jan 2025 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23671</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sav WP OpenSearch wp-opensearch allows Stored XSS.This issue affects WP OpenSearch: from n/a through <= 1.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-21545 – Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21545</guid>
    <pubDate>Tue, 21 Jan 2025 21:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-21545</strong></p>
  <p>Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a h…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55886 – OpenSearch Data Prepper is a component of the OpenSearch project that accepts, f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55886</guid>
    <pubDate>Thu, 12 Dec 2024 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55886</strong></p>
  <p>OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugins will not perform authentication. This allows unauthorized users to ingest OpenTelemetry Logs data…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43794 – OpenSearch Dashboards Security Plugin adds a configuration management UI for the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43794</guid>
    <pubDate>Fri, 23 Aug 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43794</strong></p>
  <p>OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21180 – Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21180</guid>
    <pubDate>Tue, 16 Jul 2024 23:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21180</strong></p>
  <p>Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).  Supported versions that are affected are 8.59, 8.60 and  8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than th…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39901 – OpenSearch Observability is collection of plugins and applications that visualiz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39901</guid>
    <pubDate>Tue, 09 Jul 2024 22:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39901</strong></p>
  <p>OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are inclu…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39900 – OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports fro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39900</guid>
    <pubDate>Tue, 09 Jul 2024 22:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39900</strong></p>
  <p>OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are include…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-45807 – OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45807</guid>
    <pubDate>Mon, 16 Oct 2023 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-45807</strong></p>
  <p>OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 2021. There is an issue with the implementation of tenant permissions in OpenSearch Dashboards where authenticated users with read-only access to a tenant can perform create, edit and delete operations on index metadata of dashboards and visualizations in that tenant, potentially r…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28864 – Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28864</guid>
    <pubDate>Mon, 17 Jul 2023 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28864</strong></p>
  <p>Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-31141 – OpenSearch is open-source software suite for search, analytics, and observabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31141</guid>
    <pubDate>Mon, 08 May 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-31141</strong></p>
  <p>OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the queries during extremely rare race conditions potentially leading to incorrect…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25806 – OpenSearch Security is a plugin for OpenSearch that offers encryption, authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25806</guid>
    <pubDate>Thu, 02 Mar 2023 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25806</strong></p>
  <p>OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity provider (IdP), and not other externally configured IdPs. Patches were released in ve…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23933 – OpenSearch Anomaly Detection identifies atypical data and receives automatic not...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23933</guid>
    <pubDate>Fri, 03 Feb 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23933</strong></p>
  <p>OpenSearch Anomaly Detection identifies atypical data and receives automatic notifications. There is an issue with the application of document and field level restrictions in the Anomaly Detection plugin, where users with the Anomaly Detector role can read aggregated numerical data (e.g. averages, sums) of fields that are otherwise restricted to them. This issue only affects authenticated users w…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23613 – OpenSearch is an open source distributed and RESTful search engine. In affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23613</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23613</strong></p>
  <p>OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level security (FLS) and field masking where rules written to explicitly exclude fields are not correctly applied for certain queries that rely on their auto-generated .keyword fields. This issue is only present for authenticated users with read access to the i…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-23612 – OpenSearch is an open source distributed and RESTful search engine. OpenSearch u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23612</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-23612</strong></p>
  <p>OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (IdP) when the authentication backend is SAML or OpenID Connect. There is an issue in how those claims are processed from the JWTs where the leading and trailing whitespace is trimmed, allowing users to potentially claim roles they are not assigned to i…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41917 – OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41917</guid>
    <pubDate>Wed, 16 Nov 2022 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41917</strong></p>
  <p>OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for text analysis. An issue in the implementation of this feature allows certain specially crafted queries to return a response containing the first line of text from arbitrary files. The list of potentially impacted files is…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41918 – OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41918</guid>
    <pubDate>Tue, 15 Nov 2022 23:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41918</strong></p>
  <p>OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-612</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41906 – OpenSearch Notifications is a notifications plugin for OpenSearch that enables o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41906</guid>
    <pubDate>Fri, 11 Nov 2022 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41906</strong></p>
  <p>OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could allow an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-35980 – OpenSearch Security is a plugin for OpenSearch that offers encryption, authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35980</guid>
    <pubDate>Fri, 12 Aug 2022 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-35980</strong></p>
  <p>OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an information disclosure vulnerability. Requests to an OpenSearch cluster configured with advanced access control features document level security (DLS), field level security (FLS), and/or field masking will not be filtered w…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-612</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31115 – opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31115</guid>
    <pubDate>Thu, 30 Jun 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31115</strong></p>
  <p>opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must be in control of an opensearch server and convince the victim to connect to it i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44833 – The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configurati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44833</guid>
    <pubDate>Sun, 12 Dec 2021 06:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44833</strong></p>
  <p>The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8954 – OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8954</guid>
    <pubDate>Mon, 08 Jun 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8954</strong></p>
  <p>OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-10245 – Insufficient sanitization of the query parameter in templates/html/search_opense...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10245</guid>
    <pubDate>Fri, 24 May 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-10245</strong></p>
  <p>Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1247 – The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1247</guid>
    <pubDate>Sun, 19 Apr 2015 10:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1247</strong></p>
  <p>The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote attackers to obtain sensitive information from local files via a crafted (1) http or (2) https web site.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1247">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
