Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
The product does not encrypt sensitive or critical information before storage or transmission.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://search-guard.com/cve-advisory/ | vendor advisory |
https://docs.search-guard.com/6.x-23/changelog-searchguard-6-x-23_1 | release notes vendor advisory |