Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.80% | — | Amazon Opensearch | 26/1/2023 | 17/6/2026 | OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (IdP) when the authentication backend is SAML or OpenID Connect. There is an issue in how those claims are processed from the JWTs where the leading and trailing whitespace… | |
| Modificada | Media (4.3) | 0.57% | — | Amazon Opensearch | 16/11/2022 | 17/6/2026 | OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for text analysis. An issue in the implementation of this feature allows certain specially crafted queries to return a response containing the… | |
| Modificada | Media (6.3) | 0.47% | — | Amazon Opensearch | 15/11/2022 | 17/6/2026 | OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading… | |
| Modificada | Alta (8.7) | 0.72% | — | Amazon Opensearch Notifications | 11/11/2022 | 17/6/2026 | OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could allow an existing privileged user to… | |
| Modificada | Alta (7.5) | 1.2% | — | Amazon Opensearch | 12/8/2022 | 17/6/2026 | OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an information disclosure vulnerability. Requests to an OpenSearch cluster configured with advanced access control features document level… | |
| Modificada | Alta (8.8) | 1.6% | — | Amazon Opensearch | 30/6/2022 | 17/6/2026 | opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must… | |
| Modificada | Crítica (9.8) | 1.6% | — | Amazon AWS Opensearch | 12/12/2021 | 17/6/2026 | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file. |