GHSA-wmx7-x4jp-9jgg, CVE-2022-41918
maven/org.opensearch.plugin/opensearch-security
Incorrect Authorization
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to update. There are no known workarounds for this issue.
All versions before 1.3.7, all versions starting from 2.0.0 before 2.4.0
Upgrade to versions 1.3.7, 2.4.0 or above.
2023-03-09
source |