PT-2025-48533 · Florian Bruhin · Search Guard Flx
Published
2025-12-01
·
Updated
2025-12-01
·
CVE-2025-13653
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Search Guard FLX versions 3.1.0 through 4.0.0
Description
Authenticated users can potentially access documents from data streams without proper authorization in Search Guard FLX when enterprise modules are disabled. This is achieved by submitting specifically crafted requests.
Recommendations
Versions prior to 4.0.0 should be updated.
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Search Guard Flx