{"id":"CVE-2022-41918","aliases":["GHSA-wmx7-x4jp-9jgg"],"url":"https://o3.security/vulnerability/CVE-2022-41918","summary":"Issue with fine-grained access control of indices backing data streams","details":"OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices that back data streams potentially leading to incorrect access authorization. OpenSearch 1.3.7 and 2.4.0 contain a fix for this issue. Users are advised to update. There are no known workarounds for this issue.","published":"2022-11-15T00:00:00Z","modified":"2026-08-12T13:33:27.463589Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.opensearch.plugin:opensearch-security","fixedVersion":"1.3.7"},{"ecosystem":"Maven","name":"org.opensearch.plugin:opensearch-security","fixedVersion":"2.4.0"}],"fix":{"url":"https://github.com/opensearch-project/security/commit/f7cc569c9d3fa5d5432c76c854eed280d45ce6f4","label":"opensearch-project/security@f7cc569"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41918.json"},{"type":"ADVISORY","url":"https://github.com/opensearch-project/security/security/advisories/GHSA-wmx7-x4jp-9jgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41918"},{"type":"FIX","url":"https://github.com/opensearch-project/security/commit/f7cc569c9d3fa5d5432c76c854eed280d45ce6f4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:33:27.463589Z"}}