Логотип exploitDog
bind:CVE-2024-23446
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-23446

Количество 4

Количество 4

nvd логотип

CVE-2024-23446

около 2 лет назад

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-23446

около 2 лет назад

An issue was discovered by Elastic, whereby the Detection Engine Searc ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-967w-7xjc-4wqj

около 2 лет назад

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-01379

около 2 лет назад

Уязвимость сервиса визуализации данных Kibana, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-23446

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-23446

An issue was discovered by Elastic, whereby the Detection Engine Searc ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-967w-7xjc-4wqj

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-01379

Уязвимость сервиса визуализации данных Kibana, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу