Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: floragunn
Published: 2019-08-23T13:26:46
Updated: 2024-08-04T23:49:25.010Z
Reserved: 2019-07-08T00:00:00
Link: CVE-2019-13421
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-08-23T14:15:11.467
Modified: 2024-11-21T04:24:54.660
Link: CVE-2019-13421
Redhat