CVE-2024-23447

MEDIUM

Elastic Network Drive Connector < 8.12.1 - Improper Access Control via Document Level Security

Title source: llm
STIX 2.1

Description

An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 29.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
elastic/network_drive_connector < 8.12.1
Published Feb 07, 2024
Tracked Since Feb 18, 2026