Field Level Security Leak in Search Guard by Search Guard
CVE-2019-13417
5.3MEDIUM
What is CVE-2019-13417?
Search Guard versions prior to 24.0 expose a vulnerability where the field caps and mapping API inadvertently reveal field names that should remain restricted when field level security (FLS) is activated. Although values for these fields are not disclosed, the leaking of field names could potentially aid attackers in devising unauthorized access strategies, posing a risk to sensitive data. Organizations using affected versions are advised to update to the latest release to safeguard their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Search Guard < 24.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
