CVE-2024-39901

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39901
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39901.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39901
Aliases
Published
2024-07-09T21:14:28.777Z
Modified
2025-12-05T05:23:35.695795Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
OpenSearch Observability does not properly restrict access to private tenant resources
Details

OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39901.json"
}
References

Affected packages

Git / github.com/opensearch-project/observability

Affected ranges

Type
GIT
Repo
https://github.com/opensearch-project/observability
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0.0
1.1.0.0

2.*

2.0.0.0
2.0.0.0-rc1
2.0.1.0
2.1.0.0
2.11.0.0

v1.*

v1.0.0.0-beta1
v1.12.0.0
v1.12.0.0-alpha
v1.13.0.0-alpha

Git / github.com/opensearch-project/reporting

Affected ranges

Type
GIT
Repo
https://github.com/opensearch-project/reporting
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0.0

2.*

2.1.0.0
2.2.0.0
2.2.1.0

chromium-1.*

chromium-1.12.0.0

v1.*

v1.0.0.0-rc1
v1.12.0.0
v1.13.0.0
v1.13.2.0