Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mj54-9pv2-7pc5

Опубликовано: 14 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6

Описание

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.

EPSS

Процентиль: 17%
0.00054
Низкий

6 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

nvd
3 месяца назад

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.

EPSS

Процентиль: 17%
0.00054
Низкий

6 Medium

CVSS4

Дефекты

CWE-200