org.opensearch.plugin:opensearch-security@2.10.0.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.opensearch.plugin:opensearch-security package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Uncontrolled Resource Consumption ('Resource Exhaustion')

Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') through the HTTP layer, an attacker can force an OpenSearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests.

How to fix Uncontrolled Resource Consumption ('Resource Exhaustion')?

Upgrade org.opensearch.plugin:opensearch-security to version 1.3.14, 2.11.0 or higher.

[,1.3.14) [2.0.0,2.11.0)
  • M
Improper Preservation of Permissions

Affected versions of this package are vulnerable to Improper Preservation of Permissions in the implementation of tenant permissions in OpenSearch Dashboards. An attacker can perform create, edit, and delete operations on index metadata of dashboards and visualizations in a tenant, potentially rendering them unavailable, by exploiting the fact that authenticated users with read-only access to a tenant are not properly restricted.

How to fix Improper Preservation of Permissions?

Upgrade org.opensearch.plugin:opensearch-security to version 2.11.0.0 or higher.

[,2.11.0.0)