CVE-2022-41918: Issue with fine-grained access control of indices backing data streams
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to update. There are no known workarounds for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSearchto a version that resolves this vulnerability.Fixed in 1.3.7 - Upgrade
Upgrade
OpenSearchto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Frequently Asked Questions
What is CVE-2022-41918?
CVE-2022-41918 is a vulnerability in OpenSearch where fine-grained access control rules are not correctly applied to data streams.
What software is affected by CVE-2022-41918?
Amazon Opensearch versions up to and including 1.3.7 are affected by CVE-2022-41918.
What is the severity of CVE-2022-41918?
The severity of CVE-2022-41918 is medium, with a CVSS score of 6.3.
How can I fix CVE-2022-41918?
To fix CVE-2022-41918, you should upgrade to a version of Amazon Opensearch that is not affected by the vulnerability.
Where can I find more information about CVE-2022-41918?
You can find more information about CVE-2022-41918 on the OpenSearch security advisory page and the GitHub commit linked in the references.