Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
The product does not encrypt sensitive or critical information before storage or transmission.
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
Link | Tags |
---|---|
https://search-guard.com/cve-advisory/ | vendor advisory |
https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_0 | release notes |