PT-2022-26147 · Unknown · Opensearch

Cehenkle

·

Published

2022-11-15

·

Updated

2023-07-10

·

CVE-2022-41917

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSearch versions prior to 1.3.7 OpenSearch versions prior to 2.4.0
Description An issue in OpenSearch allows certain specially crafted queries to return a response containing the first line of text from arbitrary files. The list of potentially impacted files is limited to text files with read permissions allowed in the Java Security Manager policy configuration.
Recommendations For OpenSearch versions prior to 1.3.7, upgrade to version 1.3.7 or later. For OpenSearch versions prior to 2.4.0, upgrade to version 2.4.0 or later.

Exploit

Fix

Improper Handling of Exceptional Conditions

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-41917
GHSA-W3RX-M34V-WRQX

Affected Products

Opensearch