Back to Database
Status published
Medium
CVE-2019-13417
Search Guard versions before 24.0 had an issue that field...
Vulnerability Description
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13417
Credits & Attribution
No credits recorded in the NVD database.
References
More from floragunn
View All →CVE-2025-13653
Unauthorized access to documents in data streams with specially crafted requests
Medium
4.3
CVE-2025-12149
Unauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documents
Medium
6
CVE-2025-12148
Unauthorized access to fields protected by Field Masking (FM) for fields of type IP
Medium
6
CVE-2025-12147
Unauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an object
Medium
6
CVE-2019-13423
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12...
High
8.8
Affected Vendor
floragunn
View all reports →Affected Software
Search Guard
Vulnerable Versions:
unspecified
Timeline
Official Publish:
August 12th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N