CVE-2019-13416

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-08-13 19:15

Updated : 2024-02-28 17:08


NVD link : CVE-2019-13416

Mitre link : CVE-2019-13416

CVE.ORG link : CVE-2019-13416


JSON object : View

Products Affected

search-guard

  • search_guard
CWE
NVD-CWE-Other CWE-285

Improper Authorization