Description
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
Remediation
References
https://discuss.elastic.co/t/elastic-stack-7-14-0-security-update/280344
https://security.netapp.com/advisory/ntap-20211008-0002/
https://www.elastic.co/community/security/
Related Vulnerabilities
CVE-2023-26920 Vulnerability in npm package fast-xml-parser
CVE-2021-41184 Vulnerability in npm package jquery-ui
CVE-2014-3600 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2014-6439 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2023-29924 Vulnerability in maven package tech.powerjob:powerjob