Vulnerability Database
Blog
FAQ
Docs
CVE-2021-44833
See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-44833
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44833.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-44833
Published
2021-12-12T06:15:06Z
Modified
2024-09-03T03:59:02.271762Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
References
https://github.com/opensearch-project/opensearch-cli/blob/275085730f791daccaac81c566a25f541656d9f9/commands/root.go#L43
https://github.com/opensearch-project/opensearch-cli/commit/69dc712d0d0d05dc2bc2bd0d733c73e3641b633a
Affected packages
Git
/
github.com/opensearch-project/opensearch
Affected ranges
Type
GIT
Repo
https://github.com/opensearch-project/opensearch
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
34550c5b17124ddc59458ef774f6b43a086522e3
Type
GIT
Repo
https://github.com/opensearch-project/opensearch-cli
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
69dc712d0d0d05dc2bc2bd0d733c73e3641b633a
Affected versions
1.*
1.0.0
1.0.0-alpha1
1.0.0-alpha2
1.0.0-beta1
1.0.0-rc1
v1.*
v1.0.0
v1.0.0-beta1
v1.1.0
CVE-2021-44833 - OSV