ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 3
ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 3
CVE-2024-39900
OpenSearch Dashboards Reports allows βReport Ownerβ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.
GHSA-xmvg-335g-x44q
The OpenSearch reporting plugin improperly controls tenancy access to reporting resources
ROS-20240716-01
ΠΠ½ΠΎΠΆΠ΅ΡΡΠ²Π΅Π½Π½ΡΠ΅ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ opensearch
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ | CVSS | EPSS | ΠΠΏΡΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ | |
|---|---|---|---|---|
CVE-2024-39900 OpenSearch Dashboards Reports allows βReport Ownerβ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14. | CVSS3: 5.4 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 2 Π»Π΅Ρ Π½Π°Π·Π°Π΄ | |
GHSA-xmvg-335g-x44q The OpenSearch reporting plugin improperly controls tenancy access to reporting resources | CVSS3: 5.4 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 2 Π»Π΅Ρ Π½Π°Π·Π°Π΄ | |
ROS-20240716-01 ΠΠ½ΠΎΠΆΠ΅ΡΡΠ²Π΅Π½Π½ΡΠ΅ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ opensearch | CVSS3: 5.4 | ΠΎΠΊΠΎΠ»ΠΎ 2 Π»Π΅Ρ Π½Π°Π·Π°Π΄ |
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ