Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: floragunn

Published: 2019-08-12T20:51:23

Updated: 2024-08-04T23:49:24.956Z

Reserved: 2019-07-08T00:00:00

Link: CVE-2019-13417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-12T21:15:15.407

Modified: 2023-03-02T17:59:10.467

Link: CVE-2019-13417

cve-icon Redhat

Severity : Low

Publid Date: 2019-08-13T00:00:00Z

Links: CVE-2019-13417 - Bugzilla