Vulnerability Description
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and 2.16.0 for this issue.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/opensearch-project/security-dashboards-plugin/commit/fc4f6a27
- https://github.com/opensearch-project/security-dashboards-plugin/security/adviso
FAQ
What is CVE-2024-43794?
CVE-2024-43794 is a vulnerability with a CVSS score of 6.1 (MEDIUM). OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to externa...
How severe is CVE-2024-43794?
CVE-2024-43794 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43794?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.