CVE-2022-35980

Source
https://cve.org/CVERecord?id=CVE-2022-35980
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-35980.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-35980
Aliases
Published
2022-08-12T17:40:09Z
Modified
2026-08-12T03:51:47Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OpenSearch vulnerable to Improper Authorization of Index Containing Sensitive Information
Details

OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an information disclosure vulnerability. Requests to an OpenSearch cluster configured with advanced access control features document level security (DLS), field level security (FLS), and/or field masking will not be filtered when the query's search pattern matches an aliased index. OpenSearch Dashboards creates an alias to .kibana by default, so filters with the index pattern of * to restrict access to documents or fields will not be applied. This issue allows requests to access sensitive information when customer have acted to restrict access that specific information. OpenSearch 2.2.0, which is compatible with OpenSearch Security 2.2.0.0, contains the fix for this issue. There is no recommended work around.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-612"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35980.json"
}
References

Affected packages

Git / github.com/opensearch-project/anomaly-detection

Affected ranges

Type
GIT
Repo
https://github.com/opensearch-project/anomaly-detection
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:amazon:opensearch:2.0.0:*:*:*:*:docker:*:*",
        "cpe:2.3:a:amazon:opensearch:2.1.0:*:*:*:*:docker:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.0"
        }
    ],
    "source": "CPE_STRING"
}
Type
GIT
Repo
https://github.com/opensearch-project/opensearch
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:amazon:opensearch:2.0.0:*:*:*:*:docker:*:*",
        "cpe:2.3:a:amazon:opensearch:2.1.0:*:*:*:*:docker:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.0"
        }
    ],
    "source": "CPE_STRING"
}
Type
GIT
Repo
https://github.com/opensearch-project/opensearch-ruby
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:amazon:opensearch:2.0.0:*:*:*:*:docker:*:*",
        "cpe:2.3:a:amazon:opensearch:2.1.0:*:*:*:*:docker:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.0"
        }
    ],
    "source": "CPE_STRING"
}
Type
GIT
Repo
https://github.com/opensearch-project/security
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:amazon:opensearch:2.0.0:*:*:*:*:docker:*:*",
        "cpe:2.3:a:amazon:opensearch:2.1.0:*:*:*:*:docker:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.0"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0.0
2.1.0
opensearch-api/2.*
opensearch-api/2.1.0
opensearch-aws-sigv4/1.*
opensearch-aws-sigv4/1.0.0
opensearch-dsl/0.*
opensearch-dsl/0.2.1
opensearch-ruby/2.*
opensearch-ruby/2.1.0
opensearch-transport/2.*
opensearch-transport/2.1.0
v2.*
v2.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-35980.json"