Lucene search

K
osvGoogleOSV:GHSA-45H5-R968-5XR7
HistorySep 20, 2021 - 8:29 p.m.

Exposure of sensitive information in Elasticsearch

2021-09-2020:29:40
Google
osv.dev
7

0.001 Low

EPSS

Percentile

44.6%

A flaw was discovered in Elasticsearch where document and field level security was not applied to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

0.001 Low

EPSS

Percentile

44.6%