CVE-2024-39900

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39900
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39900.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39900
Aliases
Published
2024-07-09T22:15:03Z
Modified
2024-07-11T16:03:15.252861Z
Summary
[none]
Details

OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.

References

Affected packages

Git / github.com/opensearch-project/reporting

Affected ranges

Type
GIT
Repo
https://github.com/opensearch-project/reporting
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0.0

2.*

2.1.0.0
2.2.0.0
2.2.1.0

chromium-1.*

chromium-1.12.0.0

v1.*

v1.0.0.0-rc1
v1.12.0.0
v1.13.0.0
v1.13.2.0