CVE-2024-43794: OpenSearch Dashboards Security Plugin improper validation of nextUrl can lead to external redirect
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43794?
CVE-2024-43794 is classified as a high severity vulnerability due to the potential for external redirects.
How do I fix CVE-2024-43794?
To fix CVE-2024-43794, upgrade the OpenSearch Dashboards Security Plugin to version 1.3.20 or 2.16.1 or later.
What systems are affected by CVE-2024-43794?
CVE-2024-43794 affects OpenSearch Dashboards Security Plugin versions before 1.3.20 and 2.16.1.
What kind of attacks can CVE-2024-43794 facilitate?
CVE-2024-43794 can facilitate phishing attacks by allowing an attacker to redirect users to malicious URLs.
Who is responsible for addressing CVE-2024-43794 vulnerabilities?
It is the responsibility of the users of OpenSearch Dashboards to apply the necessary updates to address CVE-2024-43794.