Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] <title>security vulnerability cve-2024-28752 #15948

Open
bhupendra-mskhatri opened this issue Sep 16, 2024 · 0 comments
Open

[BUG] <title>security vulnerability cve-2024-28752 #15948

bhupendra-mskhatri opened this issue Sep 16, 2024 · 0 comments
Labels
bug Something isn't working Plugins untriaged

Comments

@bhupendra-mskhatri
Copy link

Describe the bug

A client of ours have reported vulnerability cve-2024-28752 in index/plugins/opensearch-security/cxf-core-4.0.3.jar.
Opensearch 2.13.0
Though we would be upgrading to opensearch 2.15.0, which has the fix, it would be helpful if someone could explain whether the vulnerability was exploitable in Opensearch 2.13.0.

Related component

Plugins

To Reproduce

  1. Go to 'index/plugins/opensearch-security/'
  2. You will find cxf-core-4.0.3.jar
  3. As per https://nvd.nist.gov/vuln/detail/CVE-2024-28752 the cxf-core-4.0.3 version is vulnerable

Expected behavior

Would like to understand if the vulnerability is exploitable in Opensearch 2.13.0?

Additional Details

Plugins
Please list all plugins currently enabled.

Screenshots
If applicable, add screenshots to help explain your problem.

Host/Environment (please complete the following information):

  • OS: windows

Additional context
Add any other context about the problem here.

@bhupendra-mskhatri bhupendra-mskhatri added bug Something isn't working untriaged labels Sep 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Plugins untriaged
Projects
None yet
Development

No branches or pull requests

1 participant