org.opensearch.plugin:opensearch-security@2.7.0.0 vulnerabilities

  • latest version

    2.18.0.0

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.opensearch.plugin:opensearch-security package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Uncontrolled Resource Consumption ('Resource Exhaustion')

    Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') through the HTTP layer, an attacker can force an OpenSearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests.

    How to fix Uncontrolled Resource Consumption ('Resource Exhaustion')?

    Upgrade org.opensearch.plugin:opensearch-security to version 1.3.14, 2.11.0 or higher.

    [,1.3.14)[2.0.0,2.11.0)
    • M
    Improper Preservation of Permissions

    Affected versions of this package are vulnerable to Improper Preservation of Permissions in the implementation of tenant permissions in OpenSearch Dashboards. An attacker can perform create, edit, and delete operations on index metadata of dashboards and visualizations in a tenant, potentially rendering them unavailable, by exploiting the fact that authenticated users with read-only access to a tenant are not properly restricted.

    How to fix Improper Preservation of Permissions?

    Upgrade org.opensearch.plugin:opensearch-security to version 2.11.0.0 or higher.

    [,2.11.0.0)