PT-2025-44310 · Elastic · Search Guard
Published
2025-10-29
·
Updated
2025-10-29
·
CVE-2025-12148
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Search Guard versions 3.1.1 and earlier
Description
Field Masking (FM) rules are not properly enforced on fields of type IP (IP Address). While the content of these fields is redacted in search results, documents are still returned when searching based on specific IP values, potentially allowing reconstruction of the original field contents.
Recommendations
For versions prior to 3.1.1, avoid using Field Masking on fields of type IP (IP Address). Instead, use field level security (FLS) protection on affected fields.
Fix
Information Disclosure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Search Guard