CVE-2024-54160: XSS
Published Feb 12, 2025
·Updated
dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer.
Affected Software
1 affected component
OpenSearch Dashboards Reports<2.19.0.0
Event History
Feb 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-54160?
CVE-2024-54160 has been classified as a medium severity vulnerability due to its potential for exploitation via XSS attacks.
2
How do I fix CVE-2024-54160?
To fix CVE-2024-54160, update OpenSearch Dashboards Reports to version 2.19.0.0 or later.
3
What kind of vulnerability is CVE-2024-54160?
CVE-2024-54160 is an XSS vulnerability caused by unsanitized Markdown when previewing headers or footers.
4
Which versions of OpenSearch are affected by CVE-2024-54160?
CVE-2024-54160 affects OpenSearch Dashboards Reports versions prior to 2.19.0.0.
5
What are the potential impacts of CVE-2024-54160?
The potential impacts of CVE-2024-54160 include unauthorized execution of scripts in the context of the user's browser.