CVE-2020-5289

MEDIUM

Elide < 4.5.14 - Unauthorized Data Access via Filter Expression Side Channel

Title source: llm
STIX 2.1

Description

In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions for an inaccessible field to filter a collection. The presence or absence of models in the returned collection can be used to reconstruct the value of the inaccessible field. Resolved in Elide 4.5.14 and greater.

References (3)

Core 3

Scores

CVSS v3 6.8
EPSS 0.0125
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

Details

CWE
CWE-552 CWE-285
Status published
Products (2)
com.yahoo.elide/elide-core 0 - 4.5.14Maven
elide/elide < 4.5.14
Published Mar 30, 2020
Tracked Since Feb 18, 2026