Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13417

Опубликовано: 13 авг. 2019
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10openshift-elasticsearch-pluginNot affected
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Fix deferred
Red Hat OpenShift Container Platform 3.9openshift-elasticsearch-pluginNot affected
Red Hat OpenShift Container Platform 3.9search-guard-2Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1749222search-guard: information disclosure in field level security (FLS)

EPSS

Процентиль: 42%
0.00203
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 6 лет назад

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

CVSS3: 5.3
github
больше 3 лет назад

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

EPSS

Процентиль: 42%
0.00203
Низкий

4.3 Medium

CVSS3