Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Search-guard
Search-guard search Guard |
|
| Vendors & Products |
Search-guard
Search-guard search Guard |
Fri, 14 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices. | In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices. |
| Title | Unauthorized access to documents protected by Document-Level Security (DLS), when Signal's watches include a search query involving protected documents | Unauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documents |
Fri, 14 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices. | |
| Title | Unauthorized access to documents protected by Document-Level Security (DLS), when Signal's watches include a search query involving protected documents | |
| Weaknesses | CWE-200 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: floragunn
Published:
Updated: 2025-11-14T16:51:01.897Z
Reserved: 2025-10-24T11:00:56.054Z
Link: CVE-2025-12149
Updated: 2025-11-14T16:09:08.655Z
Status : Deferred
Published: 2025-11-14T14:15:46.270
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12149
No data.
OpenCVE Enrichment
Updated: 2025-11-15T22:07:48Z