Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-12539

Опубликовано: 17 дек. 2024
Источник: debian
EPSS Низкий

Описание

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elasticsearchremovedpackage

EPSS

Процентиль: 38%
0.00453
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
redhat
больше 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
nvd
больше 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

github
больше 1 года назад

Elasticsearch Incorrect Authorization vulnerability

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость поисковой системы Elasticsearch, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 38%
0.00453
Низкий