OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.
History

Fri, 20 Sep 2024 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Opensearch
Opensearch observability
CPEs cpe:2.3:a:opensearch:observability:*:*:*:*:*:*:*:*
Vendors & Products Opensearch
Opensearch observability

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-07-09T21:17:21.652Z

Updated: 2024-08-02T04:33:11.516Z

Reserved: 2024-07-02T19:37:18.599Z

Link: CVE-2024-39900

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:11.516Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T22:15:03.243

Modified: 2024-09-20T12:40:20.277

Link: CVE-2024-39900

cve-icon Redhat

No data.