CVE-2025-12148

In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of these fields is properly redacted in the _source document returned by search operations, the results do return documents (hits) when searching based on a specific IP values. This allows to reconstruct the original contents of the field. Workaround - If you cannot upgrade immediately, you can avoid the problem by using field level security (FLS) protection on fields of the affected types instead of field masking.
CVSS

No CVSS.

Configurations

No configuration.

History

29 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-29 16:15

Updated : 2025-10-30 15:03


NVD link : CVE-2025-12148

Mitre link : CVE-2025-12148

CVE.ORG link : CVE-2025-12148


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-732

Incorrect Permission Assignment for Critical Resource