5
CVSSv2

CVE-2019-13417

Published: 12/08/2019 Updated: 02/03/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Search Guard versions prior to 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

search-guard search guard

Vendor Advisories

Impact: Low Public Date: 2019-08-13 CWE: CWE-200 Bugzilla: 1749222: CVE-2019-13417 search-guard: inform ...