PT-2025-44310 · Elastic · Search Guard

Published

2025-10-29

·

Updated

2025-10-29

·

CVE-2025-12148

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Search Guard versions 3.1.1 and earlier
Description Field Masking (FM) rules are not properly enforced on fields of type IP (IP Address). While the content of these fields is redacted in search results, documents are still returned when searching based on specific IP values, potentially allowing reconstruction of the original field contents.
Recommendations For versions prior to 3.1.1, avoid using Field Masking on fields of type IP (IP Address). Instead, use field level security (FLS) protection on affected fields.

Fix

Information Disclosure

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-12148

Affected Products

Search Guard