Описание
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
EPSS
Процентиль: 35%
0.00415
Низкий
8.1 High
CVSS3
Дефекты
CWE-475
Связанные уязвимости
CVSS3: 8.1
github
около 1 месяца назад
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
EPSS
Процентиль: 35%
0.00415
Низкий
8.1 High
CVSS3
Дефекты
CWE-475