VendorsAmazonopensearchall versions
Vulnerabilities

Amazon Opensearch

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-31115
Unsafe YAML deserialization in opensearch-ruby
Published 2022-06-30 · Modified
8.8EPSS 0.016
CVE-2023-23612
Issue with whitespace in JWT roles in OpenSearch
Published 2023-01-24 · Modified
8.8EPSS 0.008
CVE-2025-9624
OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS
Published 2025-11-25 · Modified
8.3EPSS 0.005
CVE-2022-35980
OpenSearch vulnerable to Improper Authorization of Index Containing Sensitive Information
Published 2022-08-12 · Modified
7.5EPSS 0.012
CVE-2023-23613
Field-level security issue with .keyword fields in OpenSearch
Published 2023-01-24 · Modified
6.5EPSS 0.008
CVE-2022-41918
Issue with fine-grained access control of indices backing data streams
Published 2022-11-15 · Modified
6.3EPSS 0.005
CVE-2023-31141
OpenSearch issue with fine-grained access control during extremely rare race conditions
Published 2023-05-08 · Modified
5.9EPSS 0.005
CVE-2023-23933
Issue in Anomaly Detection with document and field level rules in numerical feature aggregations
Published 2023-02-03 · Modified
5.7EPSS 0.005
CVE-2023-45807
OpenSearch Issue with tenant read-only permissions
Published 2023-10-16 · Modified
5.4EPSS 0.004
CVE-2023-25806
Time discrepancy in authentication responses in OpenSearch
Published 2023-03-02 · Modified
5.3EPSS 0.003
CVE-2022-41917
Incorrect Error Handling Allowed Partial File Reads Over REST API in OpenSearch
Published 2022-11-15 · Modified
4.3EPSS 0.006