Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.
CVSS Information
N/A
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Elastic X-Pack Security 信息泄露漏洞
Vulnerability Description
Elastic X-Pack是荷兰Elasticsearch公司的一个Elastic Stack(日志分析系统)的扩展。Security是其中的一个用来控制访问权限的功能。 X-Pack Security 5.2.x版本中存在信息泄露漏洞。攻击者可利用该漏洞未授权访问字段。
CVSS Information
N/A
Vulnerability Type
N/A