Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mpw-4546-2wcr

Опубликовано: 17 дек. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6

Описание

Elasticsearch Incorrect Authorization vulnerability

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 8.16.0, < 8.16.2

8.16.2

EPSS

Процентиль: 56%
0.00338
Низкий

6 Medium

CVSS4

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
redhat
около 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
nvd
около 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
debian
около 1 года назад

An issue was discovered where improper authorization controls affected ...

CVSS3: 4.3
fstec
около 1 года назад

Уязвимость поисковой системы Elasticsearch, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 56%
0.00338
Низкий

6 Medium

CVSS4

Дефекты

CWE-863