An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-20949 An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2024-08-19T20:08:17.521Z

Reserved: 2024-01-16T21:31:26.030Z

Link: CVE-2024-23446

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:24.274Z

cve-icon NVD

Status : Modified

Published: 2024-02-07T04:15:07.470

Modified: 2024-11-21T08:57:43.497

Link: CVE-2024-23446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.