CVE-2023-23613

OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level security (FLS) and field masking where rules written to explicitly exclude fields are not correctly applied for certain queries that rely on their auto-generated .keyword fields. This issue is only present for authenticated users with read access to the indexes containing the restricted fields. This may expose data which may otherwise not be accessible to the user. OpenSearch 1.0.0-1.3.7 and 2.0.0-2.4.1 are affected. Users are advised to upgrade to OpenSearch 1.3.8 or 2.5.0. Users unable to upgrade may write explicit exclusion rules as a workaround. Policies authored in this way are not subject to this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:amazon:opensearch:*:*:*:*:*:-:*:*
cpe:2.3:a:amazon:opensearch:*:*:*:*:*:-:*:*

History

21 Nov 2024, 07:46

Type Values Removed Values Added
Summary
  • (es) OpenSearch es un motor de búsqueda RESTful y distribuido de código abierto. En las versiones afectadas hay un problema en la implementación de la seguridad a nivel de campo (FLS) y el enmascaramiento de campos donde las reglas escritas para excluir campos explícitamente no se aplican correctamente para ciertas consultas que dependen de sus campos .keyword generados automáticamente. Este problema solo está presente para usuarios autenticados con acceso de lectura a los índices que contienen los campos restringidos. Esto puede exponer datos a los que de otra manera el usuario no podría acceder. OpenSearch 1.0.0-1.3.7 y 2.0.0-2.4.1 se ven afectados. Se recomienda a los usuarios que actualicen a OpenSearch 1.3.8 o 2.5.0. Los usuarios que no puedan actualizar pueden escribir reglas de exclusión explícitas Como workaround. Las políticas creadas de esta manera no están sujetas a esta cuestión.
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.7
References () https://github.com/opensearch-project/OpenSearch/releases/tag/2.5.0 - Third Party Advisory () https://github.com/opensearch-project/OpenSearch/releases/tag/2.5.0 - Third Party Advisory
References () https://github.com/opensearch-project/security/security/advisories/GHSA-v3cg-7r9h-r2g6 - Third Party Advisory () https://github.com/opensearch-project/security/security/advisories/GHSA-v3cg-7r9h-r2g6 - Third Party Advisory

Information

Published : 2023-01-26 21:18

Updated : 2024-11-21 07:46


NVD link : CVE-2023-23613

Mitre link : CVE-2023-23613

CVE.ORG link : CVE-2023-23613


JSON object : View

Products Affected

amazon

  • opensearch
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor