X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.elastic.co/community/security | vendor advisory |