CNNVD-202511-1759 Information

CNNVD ID

CNNVD-202511-1759

CVE-2025-12149

  • CNNVD Published: 2025-11-14

Description (Chinese)

Floragunn Search Guard FLX是德国Floragunn公司的一款用于保护Elastic Search的安全组件。 Floragunn Search Guard FLX 3.1.2及之前版本存在安全漏洞,该漏洞源于从Signals watch触发搜索时未强制执行DLS规则,可能导致访问所有文档。

Description (English)

Floragunn Search Guard FLX is a security component of the German company Floragunn used to protect Elastic Search. There is a security loophole in Floragunn Search Guard FLX 3.1.2 and earlier versions, which stems from the failure to enforce the DLS rules when a search is triggered by Signals Watch and may lead to access to all documents.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Floragunn

Published

2025-11-14

Last Modified

2026-02-24

References

https://docs.search-guard.com/latest/changelog-searchguard-flx-3_1_3 https://docs.search-guard.com/latest/changelog-searchguard-flx-4_0_0 https://search-guard.com/cve-advisory/

Patch

https://search-guard.com/search-guard-free-trial/

Share on: