CVE-2022-41917
Last modified
CVE-2022-41917 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for text analysis. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for text analysis. An issue in the implementation of this feature allows certain specially crafted queries to return a response containing the first line of text from arbitrary files. The list of potentially impacted files is limited to text files with read permissions allowed in the Java Security Manager policy configuration. OpenSearch version 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to upgrade. There are no known workarounds for this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Opensearch | >= 1.0.0, < 1.3.7 |
| Amazon | Opensearch | >= 2.0.0, < 2.4.0 |
References
- https://github.com/opensearch-project/OpenSearch/commit/6d20423f5920745463b1abc5f1daf6a786c41aa0Patch, Third Party Advisory
- https://github.com/opensearch-project/OpenSearch/commit/6d20423f5920745463b1abc5f1daf6a786c41aa0Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41917?
How severe is CVE-2022-41917?
How do I fix CVE-2022-41917?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41911TensorFlow is an open source platform for machine learning. …7.5
- CVE-2022-41912The crewjam/saml go library prior to version 0.4.9 is vulner…9.8
- CVE-2022-41913Discourse-calendar is a plugin for the Discourse messaging p…5.4
- CVE-2022-41914Zulip is an open-source team collaboration tool. For organiz…3.7
- CVE-2022-41915Netty project is an event-driven asynchronous network applic…6.5
- CVE-2022-41916Heimdal is an implementation of ASN.1/DER, PKIX, and Kerbero…7.5
- CVE-2022-41918OpenSearch is a community-driven, open source fork of Elasti…6.3
- CVE-2022-41919Fastify is a web framework with minimal overhead and plugin …8.8
- CVE-2022-4192Use after free in Live Caption in Google Chrome prior to 108…8.8
- CVE-2022-41920Lancet is a general utility library for the go programming l…8.8
- CVE-2022-41921Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2022-41922`yiisoft/yii` before version 1.1.27 are vulnerable to Remote…9.8
Are you affected by CVE-2022-41917?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
