VDB
Sign up
MEDIUM

GHSA-5mpw-4546-2wcr

Elasticsearch Incorrect Authorization vulnerability

Quick fix

GHSA-5mpw-4546-2wcr — org.elasticsearch:elasticsearch: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.16.2</version> for org.elasticsearch:elasticsearch

Details

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.elasticsearch:elasticsearch
Introduced in: 8.16.0Fixed in: 8.16.2
Fix# pom.xml: bump <version>8.16.2</version> for org.elasticsearch:elasticsearch

References