CyberRota Analysis
AI-GeneratedThe Execute Monitor API in the Amazon OpenSearch Alerting plugin is vulnerable due to missing authorization, enabling authenticated remote users to manipulate index data by crafting specific inline monitor requests. This flaw could lead to unauthorized access, allowing attackers to read, modify, or delete sensitive data. Organizations utilizing Amazon OpenSearch should prioritize addressing this vulnerability to safeguard their data integrity and prevent potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.