OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Aug 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue. | |
Title | OpenSearch Dashboards Security Plugin improper validation of nextUrl can lead to external redirect | |
Weaknesses | CWE-601 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-23T16:15:58.428Z
Updated: 2024-08-23T17:01:06.990Z
Reserved: 2024-08-16T14:20:37.324Z
Link: CVE-2024-43794
Vulnrichment
Updated: 2024-08-23T16:56:40.784Z
NVD
Status : Awaiting Analysis
Published: 2024-08-23T17:15:10.007
Modified: 2024-08-23T18:46:31.730
Link: CVE-2024-43794
Redhat
No data.