2.18.0.0
2 years ago
2 months ago
Known vulnerabilities in the org.opensearch.plugin:opensearch-security package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') through the HTTP layer, an attacker can force an OpenSearch node to exit with an How to fix Uncontrolled Resource Consumption ('Resource Exhaustion')? Upgrade | [,1.3.14)[2.0.0,2.11.0) |
Affected versions of this package are vulnerable to Improper Preservation of Permissions in the implementation of tenant permissions in OpenSearch Dashboards. An attacker can perform create, edit, and delete operations on index metadata of dashboards and visualizations in a tenant, potentially rendering them unavailable, by exploiting the fact that authenticated users with read-only access to a tenant are not properly restricted. How to fix Improper Preservation of Permissions? Upgrade | [,2.11.0.0) |
Affected versions of this package are vulnerable to Incorrect Authorization due to an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the queries during extremely rare race conditions. Note: For this issue to be triggered, two concurrent requests need to land on the same instance exactly when query cache eviction happens, once every four hours. How to fix Incorrect Authorization? Upgrade | [2.0.0,2.7.0.0) |
Affected versions of this package are vulnerable to Timing Attack in the authentication response time, which is different for existing and not-existing users. Note: This issue only affects calls using the internal basic identity provider (IdP), not other externally configured IdPs. How to fix Timing Attack? Upgrade | [,1.3.9)[2.0.0,2.6.0) |