Moderate severityNVD Advisory· Published Dec 17, 2024· Updated Dec 17, 2024
Elasticsearch Incorrect Authorization
CVE-2024-12539
Description
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | >= 8.16.0, < 8.16.2 | 8.16.2 |
Affected products
1- Range: 8.16.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.