In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 01 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges. | |
| Title | Unauthorized access to documents in data streams with specially crafted requests | |
| Weaknesses | CWE-200 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: floragunn
Published:
Updated: 2025-12-01T18:33:42.466Z
Reserved: 2025-11-25T13:13:39.858Z
Link: CVE-2025-13653
Updated: 2025-12-01T18:33:37.868Z
Status : Received
Published: 2025-12-01T18:16:02.707
Modified: 2025-12-01T18:16:02.707
Link: CVE-2025-13653
No data.
OpenCVE Enrichment
No data.