CVE-2023-45807 is a medium-severity vulnerability affecting Amazon OpenSearch Dashboards, where authenticated users with read-only tenant access can manipulate index metadata for dashboards and visualizations, potentially causing service disruption. The attack requires low privileges and network access, with a low impact on integrity and availability, but does not affect index data or grant additional read access. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.14.0CPE matchmatch criteria | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:docker:*:* | ||
< 1.3.14.0CPE matchmatch criteria | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:maven:*:* | ||
>= 2.0.0, < 2.11.0.0CPE matchmatch criteria | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:docker:*:* | ||
>= 2.0.0, < 2.11.0.0CPE matchmatch criteria | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:maven:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.