Information disclosure in OpenSearch - CVE-2023-23613

 

Information disclosure in OpenSearch - CVE-2023-23613

Published: December 12, 2024


Vulnerability identifier: #VU101753
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23613
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to insertion of sensitive information into metadata. A remote user can send a specially-crafted request to exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.


Affected software

OpenSearch
Cognos Dashboards on Cloud Pak for Data

How to mitigate CVE-2023-23613

Install updates from vendor's website.

OpenSearch - addressed in versions 1.3.8, 2.5.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1

External References

Related Security Bulletins