CVE-2024-12539
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
17/12/2024
Last modified:
04/02/2025
Description
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* | 8.16.0 (including) | 8.16.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page