Description
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4910 | Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s). |
References
History
No history.
Status: PUBLISHED
Assigner: floragunn
Published:
Updated: 2024-08-04T23:49:24.948Z
Reserved: 2019-07-08T00:00:00.000Z
Link: CVE-2019-13416
No data.
Status : Modified
Published: 2019-08-13T19:15:16.500
Modified: 2024-11-21T04:24:54.087
Link: CVE-2019-13416
OpenCVE Enrichment
No data.
Weaknesses
EUVD