Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Aws Opensearch
cpe:2.3:a:aws:opensearch:*:*:*:*:*:*:*:*
|
2.15.0
|
3.5.0
|
|
Github Opensearch
cpe:2.3:a:github:opensearch:*:*:*:*:*:*:*:*
|
2.15.0
|
3.5.0
|