Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c6wg-cm5x-rqvj

Опубликовано: 07 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

OpenSearch has time discrepancy in authentication responses

Impact

There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity provider (IdP), and not other externally configured IdPs.

Patches

OpenSearch 1.3.9 and 2.6.0

Workarounds

None.

References

If you have any questions or comments about this advisory, please contact AWS/Amazon Security using our issue reporting page [1] or directly via email [2]. Please do not create a public GitHub issue.

[1] AWS Security issue reporting page: https://aws.amazon.com/security/vulnerability-reporting/ [2] AWS Security email: aws-security@amazon.com

Пакеты

Наименование

org.opensearch.plugin:opensearch-security

maven
Затронутые версииВерсия исправления

< 1.3.9

1.3.9

Наименование

org.opensearch.plugin:opensearch-security

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.6.0

2.6.0

EPSS

Процентиль: 46%
0.00227
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity provider (IdP), and not other externally configured IdPs. Patches were released in versions 1.3.9 and 2.6.0, there are no workarounds.

CVSS3: 5.3
redos
3 месяца назад

Уязвимость opensearch

CVSS3: 5.3
fstec
больше 2 лет назад

Уязвимость программного пакета OpenSearch, связанная с раскрытием информации через несоответствие, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 46%
0.00227
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208