Description
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4911 | Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated. |
References
History
No history.
Status: PUBLISHED
Assigner: floragunn
Published:
Updated: 2024-08-04T23:49:24.956Z
Reserved: 2019-07-08T00:00:00.000Z
Link: CVE-2019-13417
No data.
Status : Modified
Published: 2019-08-12T21:15:15.407
Modified: 2024-11-21T04:24:54.203
Link: CVE-2019-13417
OpenCVE Enrichment
No data.
EUVD