Description
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
Published: 2019-08-12
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-4911 Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
History

No history.

Subscriptions

Search-guard Search Guard
cve-icon MITRE

Status: PUBLISHED

Assigner: floragunn

Published:

Updated: 2024-08-04T23:49:24.956Z

Reserved: 2019-07-08T00:00:00.000Z

Link: CVE-2019-13417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-12T21:15:15.407

Modified: 2026-06-17T02:16:44.957

Link: CVE-2019-13417

cve-icon Redhat

Severity : Low

Publid Date: 2019-08-13T00:00:00Z

Links: CVE-2019-13417 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-863

    Incorrect Authorization