{"id":"GHSA-v3cg-7r9h-r2g6","summary":"Field-level security issue with .keyword fields in OpenSearch","details":"### Advisory title: Field-level security issue with .keyword fields\n\n### Affected versions:\nOpenSearch 1.0.0-1.3.7 and 2.0.0-2.4.1\n\n### Patched versions:\nOpenSearch 1.3.8 and 2.5.0\n\n### Impact:\nThere is an issue in the implementation of field-level security (FLS) and field masking where rules written to explicitly exclude fields are not correctly applied for certain queries that rely on their auto-generated .keyword fields.\n\nThis issue is only present for authenticated users with read access to the indexes containing the restricted fields.\n\n### Workaround:\nFLS rules that use explicit exclusions can be written to grant explicit access instead. Policies authored in this way are not subject to this issue.\n\n### Patches:\nOpenSearch versions 1.3.8 and 2.5.0 contain a fix for this issue.\n\n### For more information:\nIf you have any questions or comments about this advisory, please contact AWS/Amazon Security via our issue reporting page (https://aws.amazon.com/security/vulnerability-reporting/) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.","aliases":["CVE-2023-23613"],"modified":"2026-09-10T03:49:51.742235328Z","published":"2023-01-24T20:54:28Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-01-24T20:54:28Z","nvd_published_at":"2023-01-26T21:18:00Z","cwe_ids":["CWE-200"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/opensearch-project/security/security/advisories/GHSA-v3cg-7r9h-r2g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-23613"},{"type":"WEB","url":"https://github.com/opensearch-project/OpenSearch/releases/tag/2.5.0"},{"type":"PACKAGE","url":"https://github.com/opensearch-project/security"}],"affected":[{"package":{"name":"org.opensearch.plugin:opensearch-security","ecosystem":"Maven","purl":"pkg:maven/org.opensearch.plugin/opensearch-security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-v3cg-7r9h-r2g6/GHSA-v3cg-7r9h-r2g6.json"}},{"package":{"name":"org.opensearch.plugin:opensearch-security","ecosystem":"Maven","purl":"pkg:maven/org.opensearch.plugin/opensearch-security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.5.0"}]}],"versions":["2.1.0.0","2.2.0.0","2.2.1.0","2.3.0.0","2.4.0.0","2.4.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-v3cg-7r9h-r2g6/GHSA-v3cg-7r9h-r2g6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}