CVE-2019-13416

MEDIUM

Search Guard < 24.3 - Improper Authorization via Cross Cluster Search

Title source: llm
STIX 2.1

Description

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://search-guard.com/cve-advisory/
Release Notes, Vendor Advisory x_refsource_confirm
https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_3

Scores

CVSS v3 6.5
EPSS 0.0099
EPSS Percentile 57.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-285
Status published
Products (1)
search-guard/search_guard < 24.3
Published Aug 13, 2019
Tracked Since Feb 18, 2026