CVE-2022-41917 is a medium-severity information disclosure vulnerability affecting OpenSearch versions prior to 1.3.7 and 2.4.0. It allows authenticated attackers to craft specific queries that can return the first line of text from arbitrary local files, limited to those with read permissions under the Java Security Manager policy. The vulnerability has a CVSS score of 4.3, indicating a network attack vector with low attack complexity and low impact on confidentiality, but no impact on integrity or availability. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.3.7CPE matchmatch criteria | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.4.0CPE matchmatch criteria | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.