{"id":"CVE-2023-23613","aliases":["GHSA-v3cg-7r9h-r2g6"],"url":"https://o3.security/vulnerability/CVE-2023-23613","summary":"Field-level security issue with .keyword fields in OpenSearch","details":"### Advisory title: Field-level security issue with .keyword fields\n\n### Affected versions:\nOpenSearch 1.0.0-1.3.7 and 2.0.0-2.4.1\n\n### Patched versions:\nOpenSearch 1.3.8 and 2.5.0\n\n### Impact:\nThere is an issue in the implementation of field-level security (FLS) and field masking where rules written to explicitly exclude fields are not correctly applied for certain queries that rely on their auto-generated .keyword fields.\n\nThis issue is only present for authenticated users with read access to the indexes containing the restricted fields.\n\n### Workaround:\nFLS rules that use explicit exclusions can be written to grant explicit access instead. Policies authored in this way are not subject to this issue.\n\n### Patches:\nOpenSearch versions 1.3.8 and 2.5.0 contain a fix for this issue.\n\n### For more information:\nIf you have any questions or comments about this advisory, please contact AWS/Amazon Security via our issue reporting page (https://aws.amazon.com/security/vulnerability-reporting/) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.","published":"2023-01-24T20:33:55.673Z","modified":"2026-08-12T13:33:51.947714Z","cvss":{"score":5.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.opensearch.plugin:opensearch-security","fixedVersion":"1.3.8"},{"ecosystem":"Maven","name":"org.opensearch.plugin:opensearch-security","fixedVersion":"2.5.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/opensearch-project/OpenSearch/releases/tag/2.5.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/23xxx/CVE-2023-23613.json"},{"type":"ADVISORY","url":"https://github.com/opensearch-project/security/security/advisories/GHSA-v3cg-7r9h-r2g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-23613"},{"type":"PACKAGE","url":"https://github.com/opensearch-project/security"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:33:51.947714Z"}}