Impact
The OpenSearch Security Analytics plugin contains a missing input validation flaw in its threat intelligence feed parser. An attacker who can authenticate to the cluster can craft a URL parameter to the threat‑intel source configuration endpoint and trigger a server‑side request forgery. This can be abused to read arbitrary local files on the OpenSearch server, potentially exposing sensitive configuration or credential data. The weakness is identified as CWE‑918.
Affected Systems
The vulnerability affects the Opensearch product offered by Amazon Web Services and by GitHub. No specific product version is listed, so all deployments using the Threat Intelligence Feed Parser in the Security Analytics plugin are potentially impacted.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is classified as high severity. The EPSS score is not available, and it is not listed in CISA KEV, but the attack requires only authenticated remote access to the cluster, a condition that many users already possess. The SSRF path is exposed via the configuration API, making the vulnerability reasonably exploitable in environments where threat intel feeds are enabled.
OpenCVE Enrichment