QID 980458

QID 980458: Java (maven) Security Update for org.elasticsearch:elasticsearch (GHSA-45h5-r968-5xr7)

A flaw was discovered in Elasticsearch where document and field level security was not applied to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to GHSA-45h5-r968-5xr7 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980458

    Software Advisories
    Advisory ID Software Component Link
    GHSA-45h5-r968-5xr7 org.elasticsearch:elasticsearch URL Logo github.com/advisories/GHSA-45h5-r968-5xr7