CVE-2022-41918

Incorrect Authorization in gem/opensearch

Identifiers

CVE-2022-41918, GHSA-wmx7-x4jp-9jgg

Package Slug

gem/opensearch

Vulnerability

Incorrect Authorization

Description

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to update. There are no known workarounds for this issue.

Affected Versions

All versions before 1.3.7, all versions starting from 2.0.0 before 2.4.0

Solution

Upgrade to versions 1.3.7, 2.4.0 or above.

Last Modified

2022-11-21

source