GHSA-v3cg-7r9h-r2g6

Suggest an improvement
Source
https://github.com/advisories/GHSA-v3cg-7r9h-r2g6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-v3cg-7r9h-r2g6/GHSA-v3cg-7r9h-r2g6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-v3cg-7r9h-r2g6
Aliases
Related
Published
2023-01-24T20:54:28Z
Modified
2025-01-16T14:25:53.658457Z
Severity
  • 5.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Field-level security issue with .keyword fields in OpenSearch
Details

Advisory title: Field-level security issue with .keyword fields

Affected versions:

OpenSearch 1.0.0-1.3.7 and 2.0.0-2.4.1

Patched versions:

OpenSearch 1.3.8 and 2.5.0

Impact:

There is an issue in the implementation of field-level security (FLS) and field masking where rules written to explicitly exclude fields are not correctly applied for certain queries that rely on their auto-generated .keyword fields.

This issue is only present for authenticated users with read access to the indexes containing the restricted fields.

Workaround:

FLS rules that use explicit exclusions can be written to grant explicit access instead. Policies authored in this way are not subject to this issue.

Patches:

OpenSearch versions 1.3.8 and 2.5.0 contain a fix for this issue.

For more information:

If you have any questions or comments about this advisory, please contact AWS/Amazon Security via our issue reporting page (https://aws.amazon.com/security/vulnerability-reporting/) or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.

Database specific
{
    "nvd_published_at": "2023-01-26T21:18:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-01-24T20:54:28Z"
}
References

Affected packages

Maven / org.opensearch.plugin:opensearch-security

Package

Name
org.opensearch.plugin:opensearch-security
View open source insights on deps.dev
Purl
pkg:maven/org.opensearch.plugin/opensearch-security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.8

Maven / org.opensearch.plugin:opensearch-security

Package

Name
org.opensearch.plugin:opensearch-security
View open source insights on deps.dev
Purl
pkg:maven/org.opensearch.plugin/opensearch-security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.5.0

Affected versions

2.*

2.1.0.0
2.2.0.0
2.2.1.0
2.3.0.0
2.4.0.0
2.4.1.0