Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13416

Опубликовано: 13 авг. 2019
Источник: redhat
CVSS3: 5.3

Описание

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10openshift-elasticsearch-pluginFix deferred
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Fix deferred
Red Hat OpenShift Container Platform 3.9openshift-elasticsearch-pluginFix deferred
Red Hat OpenShift Container Platform 3.9search-guard-2Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1758313search-guard: authenticated users ignoring their roles on the remote cluster

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

github
больше 3 лет назад

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

5.3 Medium

CVSS3