Information Exposure Affecting org.opensearch.plugin:opensearch-security package, versions [,2.19.3.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGOPENSEARCHPLUGIN-11509799
  • published8 Aug 2025
  • disclosed1 Aug 2025
  • creditUnknown

Introduced: 1 Aug 2025

New CVE NOT AVAILABLE CWE-200  (opens in a new tab)

How to fix?

Upgrade org.opensearch.plugin:opensearch-security to version 2.19.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure in the process that applies field masking rules to fields of types ip, geo_point, geo_shape, xy_point, and xy_shape. An attacker can access sensitive information by issuing search queries that reconstruct the original field contents or by requesting unredacted values via the fields option of the search API.

Workaround

This vulnerability can be mitigated by using field level security (FLS) protection on fields of the affected types instead of field masking.

References

CVSS Base Scores

version 4.0
version 3.1