Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12539

Опубликовано: 17 дек. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 8.16.0 (включая) до 8.16.2 (исключая)

EPSS

Процентиль: 56%
0.00338
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
redhat
около 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
debian
около 1 года назад

An issue was discovered where improper authorization controls affected ...

github
около 1 года назад

Elasticsearch Incorrect Authorization vulnerability

CVSS3: 4.3
fstec
около 1 года назад

Уязвимость поисковой системы Elasticsearch, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 56%
0.00338
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863
CWE-863