PT-2025-44309 · Elastic · Search Guard Flx

Published

2025-10-29

·

Updated

2025-10-29

·

CVE-2025-12147

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Search Guard FLX versions 3.1.1 and earlier
Description Field-Level Security (FLS) rules are not properly enforced on object-valued fields. When an FLS exclusion rule is applied to a field containing an object, the object is removed from search results, but its members remain accessible. This allows unauthorized access to the object's attributes, potentially enabling reconstruction of the excluded object's contents.
Recommendations For versions 3.1.1 and earlier, add an additional exclusion rule for the members of the object if FLS exclusion rules are used for object-valued attributes. For example, if excluding ~object, also exclude ~object.*.

Fix

Information Disclosure

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-12147

Affected Products

Search Guard Flx