In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
History

Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Search-guard
Search-guard search Guard
Vendors & Products Search-guard
Search-guard search Guard

Fri, 14 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
Description In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices. In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Title Unauthorized access to documents protected by Document-Level Security (DLS), when Signal's watches include a search query involving protected documents Unauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documents

Fri, 14 Nov 2025 14:00:00 +0000

Type Values Removed Values Added
Description In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Title Unauthorized access to documents protected by Document-Level Security (DLS), when Signal's watches include a search query involving protected documents
Weaknesses CWE-200
CWE-863
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: floragunn

Published: 2025-11-14T13:58:42.775Z

Updated: 2025-11-14T16:51:01.897Z

Reserved: 2025-10-24T11:00:56.054Z

Link: CVE-2025-12149

cve-icon Vulnrichment

Updated: 2025-11-14T16:09:08.655Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-14T14:15:46.270

Modified: 2025-11-14T17:15:59.060

Link: CVE-2025-12149

cve-icon Redhat

No data.