CVE-2024-12539
17.12.2024, 21:15
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.Enginsight
Vendor | Product | Version |
---|---|---|
elastic | elasticsearch | 8.16.0 ≤ 𝑥 < 8.16.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases