SSL Certificate Trust Vulnerability in OpenSearch Data Prepper by OpenSearch
CVE-2025-62371
What is CVE-2025-62371?
OpenSearch Data Prepper, an open-source data collector for observability, has a vulnerability in its handling of SSL certificates. In versions before 2.12.2, both the OpenSearch sink and source plugins trust all SSL certificates by default if no certificate path is specified. This default behavior can lead to a bypass of SSL certificate validation, making the system susceptible to man-in-the-middle attacks, where attackers can intercept and alter data transmitted between OpenSearch Data Prepper and OpenSearch clusters. To mitigate this vulnerability, users should upgrade to version 2.12.2 or later or explicitly provide the certificate parameter in their configuration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
data-prepper < 2.12.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
