In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Search-guard
Search-guard search Guard |
|
| Vendors & Products |
Search-guard
Search-guard search Guard |
Mon, 01 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges. | |
| Title | Unauthorized access to documents in data streams with specially crafted requests | |
| Weaknesses | CWE-200 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: floragunn
Published: 2025-12-01T18:02:00.573Z
Updated: 2025-12-01T18:33:42.466Z
Reserved: 2025-11-25T13:13:39.858Z
Link: CVE-2025-13653
Updated: 2025-12-01T18:33:37.868Z
Status : Awaiting Analysis
Published: 2025-12-01T18:16:02.707
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-13653
No data.