{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T05:12:10.656","vulnerabilities":[{"cve":{"id":"CVE-2019-13417","sourceIdentifier":"security@search-guard.com","published":"2019-08-12T21:15:15.407","lastModified":"2024-11-21T04:24:54.203","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated."},{"lang":"es","value":"Las versiones de Search Guard anteriores a la versión 24.0 tenían el problema de que los límites de campo y los nombres de campo de fuga de API de mapeo (pero no los valores) para los campos que no están permitidos para el usuario cuando la seguridad de nivel de campo (FLS) está activada."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security@search-guard.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*","versionEndExcluding":"24.0","matchCriteriaId":"37A2E496-23EC-403E-97CE-3E70C76AB320"}]}]}],"references":[{"url":"https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_0","source":"security@search-guard.com","tags":["Release Notes"]},{"url":"https://search-guard.com/cve-advisory/","source":"security@search-guard.com","tags":["Vendor Advisory"]},{"url":"https://docs.search-guard.com/6.x-25/changelog-searchguard-6-x-24_0","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://search-guard.com/cve-advisory/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}