CVE-2023-25806

MEDIUM

OpenSearch Security - Info Disclosure

Title source: llm
STIX 2.1

Description

OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity provider (IdP), and not other externally configured IdPs. Patches were released in versions 1.3.9 and 2.6.0, there are no workarounds.

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 51.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-208 CWE-203
Status published
Products (3)
amazon/opensearch < 1.3.9
amazon/opensearch_security < 1.3.9
org.opensearch.plugin/opensearch-security 0 - 1.3.9Maven
Published Mar 02, 2023
Tracked Since Feb 18, 2026