Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12539

Опубликовано: 17 дек. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

In some versions of Elasticsearch, improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security. This may allow users to access to documents that their roles would normally not allow.

Отчет

This issue is specific to versions 8.16.0 and 8.16.1. Red Hat does not ship an affected version of this component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat Quay 3quay/quay-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2332909elasticsearch: improper auth controls can allow circumvention of Document Level Security

EPSS

Процентиль: 38%
0.00453
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
nvd
больше 1 года назад

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

CVSS3: 6.5
debian
больше 1 года назад

An issue was discovered where improper authorization controls affected ...

github
больше 1 года назад

Elasticsearch Incorrect Authorization vulnerability

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость поисковой системы Elasticsearch, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 38%
0.00453
Низкий

6.5 Medium

CVSS3