Opensearch-Project Data-Prepper vulnerabilities
2 known vulnerabilities affecting opensearch-project/data-prepper.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-62371HIGHCVSS 7.4fixed in 2.12.22025-10-15
CVE-2025-62371 [HIGH] CWE-295 CVE-2025-62371: OpenSearch Data Prepper as an open source data collector for observability data. In versions prior t
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically use a trust all SSL strategy when
cvelistv5nvd
CVE-2024-55886MEDIUMCVSS 6.9v>= 2.1.0, < 2.10.22024-12-12
CVE-2024-55886 [MEDIUM] CWE-287 CVE-2024-55886: OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms,
OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugins will not perform authentication. This allows unaut
cvelistv5nvd