Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: floragunn

Published: 2019-08-13T18:58:45

Updated: 2024-08-04T23:49:24.948Z

Reserved: 2019-07-08T00:00:00

Link: CVE-2019-13416

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-13T19:15:16.500

Modified: 2020-10-08T12:58:53.303

Link: CVE-2019-13416

cve-icon Redhat

Severity : Low

Publid Date: 2019-08-13T00:00:00Z

Links: CVE-2019-13416 - Bugzilla