OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Sep 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Opensearch
Opensearch observability |
|
CPEs | cpe:2.3:a:opensearch:observability:*:*:*:*:*:*:*:* | |
Vendors & Products |
Opensearch
Opensearch observability |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-07-09T21:17:21.652Z
Updated: 2024-08-02T04:33:11.516Z
Reserved: 2024-07-02T19:37:18.599Z
Link: CVE-2024-39900
Vulnrichment
Updated: 2024-08-02T04:33:11.516Z
NVD
Status : Modified
Published: 2024-07-09T22:15:03.243
Modified: 2024-11-21T09:28:31.610
Link: CVE-2024-39900
Redhat
No data.