PT-2023-19075 · Unknown+1 · Opensearch+1

Cehenkle

·

Publicado

2023-01-24

·

Atualizado

2025-04-03

·

CVE-2023-23613

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSearch versions 1.0.0 through 1.3.7 OpenSearch versions 2.0.0 through 2.4.1
Description There is an issue in the implementation of field-level security (FLS) and field masking where rules written to explicitly exclude fields are not correctly applied for certain queries that rely on their auto-generated .keyword fields. This issue is only present for authenticated users with read access to the indexes containing the restricted fields, which may expose data that would otherwise not be accessible to the user.
Recommendations For OpenSearch versions 1.0.0 through 1.3.7, upgrade to OpenSearch 1.3.8. For OpenSearch versions 2.0.0 through 2.4.1, upgrade to OpenSearch 2.5.0. As a temporary workaround for users unable to upgrade, consider writing explicit exclusion rules to grant explicit access instead, as policies authored in this way are not subject to this issue.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-04294
CVE-2023-23613
GHSA-V3CG-7R9H-R2G6

Produtos afetados

Opensearch
Red Os