在 OpenSearch SQL 插件的 Flint 扩展查询处理器中存在 SQL 查询验证绕过漏洞,允许具有异步查询访问权限的远程认证攻击者通过向直接查询端点发送精心构造的 SQL 查询,在 Apache Spark 工作节点上执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | Opensearch | 2.13≤ 3.5 |
affected |
| Github | Opensearch | 2.13≤ 3.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | Opensearch | 2.13 ~ 3.5 | - |
|
| Github | Opensearch | 2.13 ~ 3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet