CVE-2019-13417

MEDIUM

Search Guard < 24.0 - Unauthorized Field Name Exposure via Field Caps and Mapping API

Title source: llm
STIX 2.1

Description

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://search-guard.com/cve-advisory/

Scores

CVSS v3 5.3
EPSS 0.0110
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-863
Status published
Products (1)
search-guard/search_guard < 24.0
Published Aug 12, 2019
Tracked Since Feb 18, 2026