lowCVSS 2.2Vulnerability

GHSA-22vx-2x23-98w6

### Description A flaw was identified in the OpenSearch Security plugin's handling of index rollover requests. When a rollover request included an explicit target index name, the security plugin did not properly evaluate access control permissions against the target index. This could allow a user with rollover permissions on a source index to create a new index with a name they are not authorized to use. ### Impact A user with `indices:admin/rollover` permission on a source index pattern could roll over to a target index name outside their authorized index patterns. This is limited to index creation via the rollover API and requires the user to already have rollover privileges on the source index. ### Patches This issue is fixed in OpenSearch 2.19.4 and 3.2.0 ### Workarounds Grant the `indices:admin/rollover` permission only to fully trusted users.

Properties

ghsa_id
GHSA-22vx-2x23-98w6
severity
low
summary
OpenSearch vulnerable to improper authorization for Rollover Requests
cvss_score
2.2
cve_id
GHSA-22vx-2x23-98w6
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-05-07T00:08:04Z
source_url
https://github.com/advisories/GHSA-22vx-2x23-98w6
ghsa_updated
2026-05-07T00:08:06Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]maven/org.opensearch.plugin:opensearch-security

AFFECTS (1)

[Software]maven/org.opensearch.plugin:opensearch-security

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-22vx-2x23-98w6 (CVSS 2.2) — Ninja Signal Threat Intelligence | Ninja Signal