Vulnerabilities > CVE-2021-31828 - Server-Side Request Forgery (SSRF) vulnerability in Amazon Open Distro

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
amazon
CWE-918

Summary

An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.

Common Weakness Enumeration (CWE)