In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
CVSS
No CVSS.
References
Configurations
No configuration.
History
14 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices. |
14 Nov 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-14 14:15
Updated : 2025-11-14 17:15
NVD link : CVE-2025-12149
Mitre link : CVE-2025-12149
CVE.ORG link : CVE-2025-12149
JSON object : View
Products Affected
No product.
