Skip to content

Sensitive Data: OpenSearch Dashboard - Default Login

Identifier: opensearch_dashboard_default_login

Scanner(s) Support

GraphQL Scanner REST Scanner WebApp Scanner ASM Scanner

Description

OpenSearch Dashboard may be accessible with default credentials, allowing unauthorized access to search analytics, visualization dashboards, and administrative functions.

How we test: We attempt to authenticate to the OpenSearch Dashboard interface using common default username and password combinations such as admin:admin. If authentication succeeds, we report the vulnerability.

Reference:

Configuration

Example

Example configuration:

---
security_tests:
  opensearch_dashboard_default_login:
    skip: false

Reference

skip

Type : boolean

Skip the test if true.