Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7rg-2hpc-fj28

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

EPSS

Процентиль: 42%
0.00203
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
redhat
больше 6 лет назад

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

CVSS3: 5.3
nvd
больше 6 лет назад

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

EPSS

Процентиль: 42%
0.00203
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200