In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-11-14 14:15
Updated : 2025-11-14 17:15
NVD link : CVE-2025-12149
Mitre link : CVE-2025-12149
CVE.ORG link : CVE-2025-12149
JSON object : View
Products Affected
No product.
