Show plain JSON{"id": "CVE-2019-13416", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 3.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.5, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 2.8}]}, "published": "2019-08-13T19:15:16.500", "references": [{"url": "https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_3", "tags": ["Release Notes", "Vendor Advisory"], "source": "security@search-guard.com"}, {"url": "https://search-guard.com/cve-advisory/", "tags": ["Vendor Advisory"], "source": "security@search-guard.com"}, {"url": "https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_3", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://search-guard.com/cve-advisory/", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "security@search-guard.com", "description": [{"lang": "en", "value": "CWE-285"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s)."}, {"lang": "es", "value": "Search Guard versiones anteriores a la 24.3 ten\u00edan un problema cuando Cross Cluster Search (CCS) estaba habilitado, los usuarios autenticados siempre est\u00e1n autorizados en el cl\u00faster local ignorando sus roles en los cl\u00fasteres remotos."}], "lastModified": "2024-11-21T04:24:54.087", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C6B3FE1-AB00-462F-B362-6F4CDA0139A6", "versionEndExcluding": "24.3"}], "operator": "OR"}]}], "sourceIdentifier": "security@search-guard.com"}