CVE Database
/

CVE-2024-12539

Back to search

CVE-2024-12539

Published: Dec 17, 2024

Modified: Dec 17, 2024

PUBLISHED

Description

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

VendorProductVersions

Elastic

Elasticsearch

affected
8.16.0 - <= 8.16.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now