In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which allows authenticated users to use specially crafted requests to read documents from data streams without having the respective privileges.
References
Configurations
No configuration.
History
01 Dec 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-01 18:16
Updated : 2025-12-02 17:16
NVD link : CVE-2025-13653
Mitre link : CVE-2025-13653
CVE.ORG link : CVE-2025-13653
JSON object : View
Products Affected
No product.
