Miggo Logo

CVE-2023-45807: OpenSearch Issue with tenant read-only permissions

5.4

CVSS Score
3.1

Basic Information

EPSS Score
0.25848%
Published
10/17/2023
Updated
11/4/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.opensearch.plugin:opensearch-securitymaven>= 2.0.0.0, < 2.11.0.02.11.0.0
org.opensearch.plugin:opensearch-securitymaven< 1.3.14.01.3.14.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t T**r* is *n issu* wit* t** impl*m*nt*tion o* t*n*nt p*rmissions in Op*nS**r** **s**o*r*s w**r* *ut**nti**t** us*rs wit* r***-only ****ss to * t*n*nt **n p*r*orm *r**t*, **it *n* **l*t* op*r*tions on in**x m*t***t* o* **s**o*r*s *n* visu*li

Reasoning

No *n*lysis *v*il**l*