Description
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-863 Incorrect Authorization
Product status
1.0.0 (semver)
References
search-guard.com/cve-advisory/
docs.search-guard.com/latest/changelog-searchguard-flx-3_1_3
docs.search-guard.com/latest/changelog-searchguard-flx-4_0_0