SCA: security update for org.opensearch.plugin:opensearch-security (GHSA-c6wg-cm5x-rqvj)

medium Tenable Cloud Security Plugin ID 413729

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization.
There is an observable discrepancy in the authentication response time between calls where the user
provided exists and calls where it does not. This issue only affects calls using the internal basic
identity provider (IdP), and not other externally configured IdPs. Patches were released in versions 1.3.9
and 2.6.0, there are no workarounds. (CVE-2023-25806)

See Also

https://github.com/advisories/GHSA-c6wg-cm5x-rqvj

Plugin Details

Severity: Medium

ID: 413729

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2023-25806

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/7/2023

Vulnerability Publication Date: 3/2/2023

Reference Information

CVE: CVE-2023-25806