Impact
Authorized attackers can bypass authentication checks in the search-center service to read any Elasticsearch index by providing an index name in the POST /search/{indexName} request or the GET /agg/requestStat/{indexName}/{routing} URL. This allows the attacker to retrieve sensitive data, including user records and password hashes, from indices such as sys_user.
Affected Systems
The vulnerability affects the zlt2000 microservices-platform product, versions up to and including 6.0.0. No other versions were identified as vulnerable in the provided data.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of data breach. The EPSS score of less than 1% suggests that exploitation is currently unlikely, yet the vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated access to the microservices platform and can trigger the exploit by sending specific POST or GET requests to the search-center service. No additional system or network conditions are required, and the exploit path is fully documented in the references.
OpenCVE Enrichment