
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow. The vulnerability affects Elasticsearch versions 8.16.0 and 8.16.1, and was assigned CVE-2024-12539 with a CVSS v4.0 score of 6.0 (Medium) and CVSS v3.1 score of 6.5 (Medium) (NVD, Elastic Advisory).
The vulnerability stems from improper authorization controls that affect specific queries in Elasticsearch. The issue specifically impacts users utilizing Document Level Security features in Elasticsearch. The vulnerability has been assigned CWE-863 (Incorrect Authorization) and received a CVSS v3.1 base score of 6.5 with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating network accessibility, low attack complexity, and high impact on confidentiality (NVD).
If exploited, this vulnerability allows malicious actors to bypass Document Level Security controls and access documents that their roles would normally not permit. The primary impact is on data confidentiality, with no direct effect on system integrity or availability (Elastic Advisory).
The vulnerability has been fixed in Elasticsearch versions 8.16.2 and 8.17.0. Users running affected versions (8.16.0 and 8.16.1) should upgrade to these patched versions to mitigate the risk (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”