An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: elastic
Published: 2024-02-07T03:16:39.182Z
Updated: 2024-08-19T20:08:17.521Z
Reserved: 2024-01-16T21:31:26.030Z
Link: CVE-2024-23446
Vulnrichment
Updated: 2024-08-01T23:06:24.274Z
NVD
Status : Modified
Published: 2024-02-07T04:15:07.470
Modified: 2024-11-21T08:57:43.497
Link: CVE-2024-23446
Redhat
No data.