In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Search-Guard Flx
cpe:2.3:a:search-guard:flx:*:*:*:*:*:*:*:*
|
3.0.0
|
4.1.0
|