CVE-2019-13416

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).
Configurations

Configuration 1 (hide)

cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:24

Type Values Removed Values Added
References () https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_3 - Release Notes, Vendor Advisory () https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_3 - Release Notes, Vendor Advisory
References () https://search-guard.com/cve-advisory/ - Vendor Advisory () https://search-guard.com/cve-advisory/ - Vendor Advisory

Information

Published : 2019-08-13 19:15

Updated : 2024-11-21 04:24


NVD link : CVE-2019-13416

Mitre link : CVE-2019-13416

CVE.ORG link : CVE-2019-13416


JSON object : View

Products Affected

search-guard

  • search_guard
CWE
CWE-285

Improper Authorization

NVD-CWE-Other