CVE-2021-44833
CRITICALAmazon AWS OpenSearch CLI 1.0.0 - Incorrect Default Permissions
Title source: llmDescription
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/opensearch-project/opensearch-cli/blob/275085730f791daccaac81c566a25f541656d9f9/commands/root.go#L43
Patch, Third Party Advisory x_refsource_misc
https://github.com/opensearch-project/opensearch-cli/commit/69dc712d0d0d05dc2bc2bd0d733c73e3641b633a
Scores
CVSS v3
9.8
EPSS
0.0029
EPSS Percentile
51.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-276
Status
published
Products (1)
amazon/aws_opensearch
1.0.0
Published
Dec 12, 2021
Tracked Since
Feb 18, 2026