CyberRota Analysis
AI-GeneratedThe OpenSearch SQL plugin is vulnerable to unrestricted deserialization of untrusted data, allowing remote authenticated users with basic read/search permissions to execute arbitrary code on the server by manipulating the cursor parameter. This high-severity flaw poses a significant risk to server integrity and data security. Organizations using the OpenSearch SQL plugin should prioritize patching this vulnerability to mitigate potential exploitation.
Original NVD Description
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.