ZeroHour

CVE-2019-13416

CVSS 3.1
6.5 medium
EPSS
<1%p60
Published
()
Modified
Description

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

Vendors
search-guard
Products
search guard
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.