Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: floragunn

Published: 2019-08-13T18:58:45

Updated: 2019-08-13T18:58:45

Reserved: 2019-07-08T00:00:00


Link: CVE-2019-13416

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-08-13T19:15:16.500

Modified: 2020-10-08T12:58:53.303


Link: CVE-2019-13416

JSON object: View

cve-icon Redhat Information

No data.