Описание
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
Ссылки
- ExploitThird Party Advisory
- https://github.com/opensearch-project/opensearch-cli/commit/69dc712d0d0d05dc2bc2bd0d733c73e3641b633aPatchThird Party Advisory
- ExploitThird Party Advisory
- https://github.com/opensearch-project/opensearch-cli/commit/69dc712d0d0d05dc2bc2bd0d733c73e3641b633aPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:amazon:aws_opensearch:1.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00285
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-276
Связанные уязвимости
github
около 4 лет назад
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
EPSS
Процентиль: 51%
0.00285
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-276