Back

MEDIUM

search-guard: authenticated users ignoring their roles on the remote cluster

Published Aug 13, 2019

Description

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner floragunn
Published Aug 13, 2019
Updated Aug 4, 2024
Reserved Jul 8, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 13, 2019
ENISA EUVD
Assigner floragunn
Published Aug 13, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-4910