Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12539

Опубликовано: 17 дек. 2024
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

Отчет

This issue is specific to versions 8.16.0 and 8.16.1. Red Hat does not ship an affected version of this component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat Quay 3quay/quay-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2332909elasticsearch: improper auth controls can allow circumvention of Document Level Security

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
nvd
около 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
debian
около 1 года назад

An issue was discovered where improper authorization controls affected ...

github
около 1 года назад

Elasticsearch Incorrect Authorization vulnerability

CVSS3: 4.3
fstec
около 1 года назад

Уязвимость поисковой системы Elasticsearch, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к защищаемой информации

6.5 Medium

CVSS3