Vulnerability Description
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Related Weaknesses (CWE)
References
- https://docs.search-guard.com/latest/changelog-searchguard-flx-3_1_3
- https://docs.search-guard.com/latest/changelog-searchguard-flx-4_0_0
- https://search-guard.com/cve-advisory/
FAQ
What is CVE-2025-12149?
CVE-2025-12149 is a documented vulnerability. In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, al...
How severe is CVE-2025-12149?
CVSS scoring is not yet available for CVE-2025-12149. Check NVD for updates.
Is there a patch for CVE-2025-12149?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.