CVE 6 MEDIUM

Unauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documents_CVE-2025-12149

6 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.

Basic Information

ID CVE-2025-12149
Source floragunn
Published Nov 14, 2025 at 13:58
Modified Nov 14, 2025 at 16:51

Affected Product

Vendor floragunn
Product Search Guard FLX
Version 1.0.0
Affected Versions floragunn Search Guard FLX 1.0.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.