CVE-2019-13417

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
Configurations

Configuration 1 (hide)

cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-08-12 21:15

Updated : 2024-02-04 20:20


NVD link : CVE-2019-13417

Mitre link : CVE-2019-13417

CVE.ORG link : CVE-2019-13417


JSON object : View

Products Affected

search-guard

  • search_guard
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-863

Incorrect Authorization