In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices. | |
| Title | Unauthorized access to documents protected by Document-Level Security (DLS), when Signal's watches include a search query involving protected documents | |
| Weaknesses | CWE-200 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: floragunn
Published:
Updated: 2025-11-14T13:58:42.775Z
Reserved: 2025-10-24T11:00:56.054Z
Link: CVE-2025-12149
No data.
Status : Received
Published: 2025-11-14T14:15:46.270
Modified: 2025-11-14T14:15:46.270
Link: CVE-2025-12149
No data.
OpenCVE Enrichment
No data.