In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address).

While the content of these fields is properly redacted in the _source document returned by search operations, the results do return documents (hits) when searching based on a specific IP values. This allows to reconstruct the original contents of the field.

Workaround - If you cannot upgrade immediately, you can avoid the problem by using field level security (FLS) protection on fields of the affected types instead of field masking.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 15:45:00 +0000

Type Values Removed Values Added
Description In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of these fields is properly redacted in the _source document returned by search operations, the results do return documents (hits) when searching based on a specific IP values. This allows to reconstruct the original contents of the field. Workaround - If you cannot upgrade immediately, you can avoid the problem by using field level security (FLS) protection on fields of the affected types instead of field masking.
Title Unauthorized access to fields protected by Field Masking (FM) for fields of type IP
Weaknesses CWE-200
CWE-732
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: floragunn

Published:

Updated: 2025-10-29T16:11:51.396Z

Reserved: 2025-10-24T11:00:54.862Z

Link: CVE-2025-12148

cve-icon Vulnrichment

Updated: 2025-10-29T16:11:15.835Z

cve-icon NVD

Status : Received

Published: 2025-10-29T16:15:33.743

Modified: 2025-10-29T16:15:33.743

Link: CVE-2025-12148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.