CVE-2024-55886Improper Authentication in Opensearch Data Prepper

Severity
6.9MEDIUMNVD
EPSS
0.4%
top 39.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugins will not perform authentication. This allows unauthorized users to ingest OpenTelemetry Logs data under certain conditions. This vulnerability does not affect the built-in `http_basic` authenticatio

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:HExploitability: 1.6 | Impact: 4.7

Affected Packages2 packages

CVEListV5opensearch-project/data-prepper>= 2.1.0, < 2.10.2
NVDamazon/opensearch_data_prepper2.1.02.10.2

🔴Vulnerability Details

1
CVEList
OpenTelemetry Logs source may lack authentication with some custom plugins2024-12-12
CVE-2024-55886 — Improper Authentication | cvebase