First published: Sun Dec 12 2021(Updated: )
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon AWS OpenSearch | =1.0.0 |
https://github.com/opensearch-project/opensearch-cli/commit/69dc712d0d0d05dc2bc2bd0d733c73e3641b633a
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44833 is a vulnerability in the CLI 1.0.0 for Amazon AWS OpenSearch that causes weak permissions for the configuration file.
CVE-2021-44833 has a severity rating of critical with a CVSS score of 9.8.
CVE-2021-44833 allows an attacker to exploit weak permissions on the configuration file.
Currently, there are no official fixes available for CVE-2021-44833. It's recommended to follow the Amazon AWS OpenSearch documentation for updates and security recommendations.
Yes, additional information about CVE-2021-44833 can be found in the references provided: [Link 1](https://github.com/opensearch-project/opensearch-cli/blob/275085730f791daccaac81c566a25f541656d9f9/commands/root.go#L43) and [Link 2](https://github.com/opensearch-project/opensearch-cli/commit/69dc712d0d0d05dc2bc2bd0d733c73e3641b633a).