QID 980458
QID 980458: Java (maven) Security Update for org.elasticsearch:elasticsearch (GHSA-45h5-r968-5xr7)
A flaw was discovered in Elasticsearch where document and field level security was not applied to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-45h5-r968-5xr7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-45h5-r968-5xr7 -
github.com/advisories/GHSA-45h5-r968-5xr7
CVEs related to QID 980458
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-45h5-r968-5xr7 | org.elasticsearch:elasticsearch |
|