« Volver al listado

CVE-2019-13417

Estado: ModificadaMedia (5.3)—

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-13417",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@search-guard.com",
      "affectedData": [
        {
          "vendor": "floragunn",
          "product": "Search Guard",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "24.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-08-12T21:15:15.407",
  "references": [
    {
      "url": "https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_0",
      "tags": [
        "Release Notes"
      ],
      "source": "security@search-guard.com"
    },
    {
      "url": "https://search-guard.com/cve-advisory/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@search-guard.com"
    },
    {
      "url": "https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_0",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://search-guard.com/cve-advisory/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@search-guard.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated."
    },
    {
      "lang": "es",
      "value": "Las versiones de Search Guard anteriores a la versión 24.0 tenían el problema de que los límites de campo y los nombres de campo de fuga de API de mapeo (pero no los valores) para los campos que no están permitidos para el usuario cuando la seguridad de nivel de campo (FLS) está activada."
    }
  ],
  "lastModified": "2026-06-17T02:16:44.957",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37A2E496-23EC-403E-97CE-3E70C76AB320",
              "versionEndExcluding": "24.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@search-guard.com"
}