Amazon Opensearch Data Prepper vulnerabilities
3 known vulnerabilities affecting amazon/opensearch_data_prepper.
Total CVEs
3
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-62371HIGHCVSS 7.4fixed in 2.12.22025-10-15
CVE-2025-62371 [HIGH] CWE-295 CVE-2025-62371: OpenSearch Data Prepper as an open source data collector for observability data. In versions prior t
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically use a trust all SSL strategy when
nvd
CVE-2024-55886MEDIUMCVSS 6.9≥ 2.1.0, < 2.10.22024-12-12
CVE-2024-55886 [MEDIUM] CWE-287 CVE-2024-55886: OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms,
OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugins will not perform authentication. This allows unaut
nvd
CVE-2023-44487HIGHCVSS 7.5KEVPoCfixed in 2.5.02023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd