CVE-2019-13417

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
Configurations

Configuration 1 (hide)

cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:24

Type Values Removed Values Added
References () https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_0 - Release Notes () https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_0 - Release Notes
References () https://search-guard.com/cve-advisory/ - Vendor Advisory () https://search-guard.com/cve-advisory/ - Vendor Advisory

Information

Published : 2019-08-12 21:15

Updated : 2024-11-21 04:24


NVD link : CVE-2019-13417

Mitre link : CVE-2019-13417

CVE.ORG link : CVE-2019-13417


JSON object : View

Products Affected

search-guard

  • search_guard
CWE
CWE-863

Incorrect Authorization

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor