PT-2024-36601 · Opensearch · Opensearch Data Prepper

Cwperks

·

Published

2024-12-12

·

Updated

2025-12-04

·

CVE-2024-55886

CVSS v3.1

6.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions OpenSearch Data Prepper versions 2.1.0 through 2.10.1
Description A vulnerability exists in the OpenTelemetry Logs source in Data Prepper where some custom authentication plugins will not perform authentication, allowing unauthorized users to ingest OpenTelemetry Logs data under certain conditions. This issue does not affect the built-in http basic authentication provider in Data Prepper. The vulnerability exists only for custom implementations of Data Prepper’s GrpcAuthenticationProvider authentication plugin which implement the getHttpAuthenticationService() method instead of getAuthenticationInterceptor().
Recommendations For versions 2.1.0 through 2.10.1, consider upgrading to Data Prepper 2.10.2, which contains a fix for this issue. As a temporary workaround, use the built-in http basic authentication provider in Data Prepper. Add an authentication proxy in front of Data Prepper instances running the OpenTelemetry Logs source to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-55886
GHSA-725P-63VV-V948

Affected Products

Opensearch Data Prepper