In Elasticsearch versions starting from 8.16.0 before 8.16.2 a medium severity vulnerability CVE-2024-12539 was detected. This vulnerability allows attackers to bypass Document Level Security controls and access restricted documents due to improper authorization checks. To address this issue, users should upgrade Elasticsearch to version 8.16.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12539.
Elasticsearch: Document Level Security Bypass Vulnerability
by the Hossted team
19.12.2024