THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-39900

OpenSearch Dashboards Reports does not properly restrict access to private tenant resources

AssignerGitHub_M
Reserved2024-07-02
Published2024-07-09
Updated2024-07-10

Description

OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.



MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-639: Authorization Bypass Through User-Controlled Key

Product status

< 2.14.0.0
affected

References

https://github.com/opensearch-project/reporting/security/advisories/GHSA-xmvg-335g-x44q

https://github.com/opensearch-project/reporting/commit/2403014c57ee63268e83d919db3334b676a8c992

https://opensearch.org/versions/opensearch-2-14-0.html

cve.org CVE-2024-39900

nvd.nist.gov CVE-2024-39900

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-39900
© Copyright 2024 THREATINT. Made in Cyprus with +