CVE-2019-13415
Status: ModifiedMedium (6.5)—
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are not authorized to see.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.99%
- Percentile among all scored CVEs: 61
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-280
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-13415",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@search-guard.com",
"affectedData": [
{
"vendor": "floragunn",
"product": "Search Guard",
"versions": [
{
"status": "affected",
"version": "before 24.3"
}
]
}
]
}
],
"published": "2019-08-13T19:15:16.407",
"references": [
{
"url": "https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_3",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "security@search-guard.com"
},
{
"url": "https://search-guard.com/cve-advisory/",
"tags": [
"Vendor Advisory"
],
"source": "security@search-guard.com"
},
{
"url": "https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_3",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://search-guard.com/cve-advisory/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@search-guard.com",
"description": [
{
"lang": "en",
"value": "CWE-280"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are not authorized to see."
},
{
"lang": "es",
"value": "Search Guard versiones anteriores a la 24.3 tenían un problema cuando Cross Cluster Search (CCS) estaba habilitado, los usuarios autenticados pueden obtener acceso de lectura a los datos que no están autorizados a ver."
}
],
"lastModified": "2026-06-17T02:16:44.740",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C6B3FE1-AB00-462F-B362-6F4CDA0139A6",
"versionEndExcluding": "24.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@search-guard.com"
}