PT-2025-44309 · Elastic · Search Guard Flx
Published
2025-10-29
·
Updated
2025-10-29
·
CVE-2025-12147
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Search Guard FLX versions 3.1.1 and earlier
Description
Field-Level Security (FLS) rules are not properly enforced on object-valued fields. When an FLS exclusion rule is applied to a field containing an object, the object is removed from search results, but its members remain accessible. This allows unauthorized access to the object's attributes, potentially enabling reconstruction of the excluded object's contents.
Recommendations
For versions 3.1.1 and earlier, add an additional exclusion rule for the members of the object if FLS exclusion rules are used for object-valued attributes. For example, if excluding
~object, also exclude ~object.*.Fix
Information Disclosure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Search Guard Flx