PT-2023-19075 · Unknown+1 · Opensearch+1
Cehenkle
·
Publicado
2023-01-24
·
Atualizado
2025-04-03
·
CVE-2023-23613
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSearch versions 1.0.0 through 1.3.7
OpenSearch versions 2.0.0 through 2.4.1
Description
There is an issue in the implementation of field-level security (FLS) and field masking where rules written to explicitly exclude fields are not correctly applied for certain queries that rely on their auto-generated
.keyword fields. This issue is only present for authenticated users with read access to the indexes containing the restricted fields, which may expose data that would otherwise not be accessible to the user.Recommendations
For OpenSearch versions 1.0.0 through 1.3.7, upgrade to OpenSearch 1.3.8.
For OpenSearch versions 2.0.0 through 2.4.1, upgrade to OpenSearch 2.5.0.
As a temporary workaround for users unable to upgrade, consider writing explicit exclusion rules to grant explicit access instead, as policies authored in this way are not subject to this issue.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opensearch
Red Os