Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read lo…
高危 CVSS 8.1
摘要
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://aws.amazon.com/security/security-bulletins/2026-079-aws/
- https://docs.aws.amazon.com/opensearch-service/latest/developerguide/service-software.html
- https://github.com/opensearch-project/security-analytics/security/advisories/GHSA-w946-8jxc-6v3m
时间线
- nvd_ingest NVD