Description
OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2451 | OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14. |
Github GHSA |
GHSA-xmvg-335g-x44q | The OpenSearch reporting plugin improperly controls tenancy access to reporting resources |
References
History
Fri, 20 Sep 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensearch
Opensearch observability |
|
| CPEs | cpe:2.3:a:opensearch:observability:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensearch
Opensearch observability |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:33:11.516Z
Reserved: 2024-07-02T19:37:18.599Z
Link: CVE-2024-39900
Updated: 2024-08-02T04:33:11.516Z
Status : Modified
Published: 2024-07-09T22:15:03.243
Modified: 2024-11-21T09:28:31.610
Link: CVE-2024-39900
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA