PT-2024-36601 · Opensearch · Opensearch Data Prepper
Cwperks
·
Published
2024-12-12
·
Updated
2025-12-04
·
CVE-2024-55886
CVSS v3.1
6.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSearch Data Prepper versions 2.1.0 through 2.10.1
Description
A vulnerability exists in the OpenTelemetry Logs source in Data Prepper where some custom authentication plugins will not perform authentication, allowing unauthorized users to ingest OpenTelemetry Logs data under certain conditions. This issue does not affect the built-in
http basic authentication provider in Data Prepper. The vulnerability exists only for custom implementations of Data Prepper’s GrpcAuthenticationProvider authentication plugin which implement the getHttpAuthenticationService() method instead of getAuthenticationInterceptor().Recommendations
For versions 2.1.0 through 2.10.1, consider upgrading to Data Prepper 2.10.2, which contains a fix for this issue.
As a temporary workaround, use the built-in
http basic authentication provider in Data Prepper.
Add an authentication proxy in front of Data Prepper instances running the OpenTelemetry Logs source to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensearch Data Prepper