CVE-2022-31115 is an unsafe deserialization vulnerability in opensearch-ruby versions 2.0.0 and prior, affecting the Amazon OpenSearch client library. It arises from the use of YAML.load instead of YAML.safe_load when processing YAML responses. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a critical risk. An attacker must control an OpenSearch server and trick a victim into connecting to it, leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability. Users are advised to upgrade to opensearch-ruby gem version 2.0.1 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.2CPE matchmatch criteria | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.