Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40453 | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue. |
Fri, 23 Aug 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue. | |
| Title | OpenSearch Dashboards Security Plugin improper validation of nextUrl can lead to external redirect | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-23T17:01:06.990Z
Reserved: 2024-08-16T14:20:37.324Z
Link: CVE-2024-43794
Updated: 2024-08-23T16:56:40.784Z
Status : Deferred
Published: 2024-08-23T17:15:10.007
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-43794
No data.
OpenCVE Enrichment
No data.
EUVD