Amazon / Opensearch
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-9624 | OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS | HIGH | 8.3 | Nov 25, 2025 |
| CVE-2023-45807 | OpenSearch Issue with tenant read-only permissions | MEDIUM | 5.4 | Oct 16, 2023 |
| CVE-2023-31141 | OpenSearch issue with fine-grained access control during extremely rare race conditions | MEDIUM | 5.9 | May 8, 2023 |
| CVE-2023-25806 | Time discrepancy in authentication responses in OpenSearch | MEDIUM | 5.3 | Mar 2, 2023 |
| CVE-2023-23933 | Issue in Anomaly Detection with document and field level rules in numerical feature aggregations | MEDIUM | 4.3 | Feb 3, 2023 |
| CVE-2023-23612 | Issue with whitespace in JWT roles in OpenSearch | HIGH | 8.8 | Jan 24, 2023 |
| CVE-2023-23613 | Field-level security issue with .keyword fields in OpenSearch | MEDIUM | 6.5 | Jan 24, 2023 |
| CVE-2022-41918 | Issue with fine-grained access control of indices backing data streams | MEDIUM | 6.3 | Nov 15, 2022 |
| CVE-2022-41917 | Incorrect Error Handling Allowed Partial File Reads Over REST API in OpenSearch | MEDIUM | 4.3 | Nov 15, 2022 |
| CVE-2022-35980 | OpenSearch vulnerable to Improper Authorization of Index Containing Sensitive Information | HIGH | 7.5 | Aug 12, 2022 |
| CVE-2022-31115 | Unsafe YAML deserialization in opensearch-ruby | HIGH | 8.8 | Jun 30, 2022 |
Showing 1 to 11 of 11 CVEs