CVE-2019-13417

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*

Information

Published : 2019-08-12 14:15

Updated : 2023-03-02 09:59


NVD link : CVE-2019-13417

Mitre link : CVE-2019-13417


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

search-guard

  • search_guard