Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30480
HistoryMay 17, 2021 - 7:46 a.m.

Information Disclosure

2021-05-1707:46:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.001 Low

EPSS

Percentile

38.9%

elasticsearch is vulnerable to information disclosure. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries when Document or Field Level Security is used, resulting in the search disclosing the existence of documents a user should not be able to view.

CPENameOperatorVersion
securityle7.11.1
securityle6.8.14

0.001 Low

EPSS

Percentile

38.9%