CVE-2023-46666: Elastic Sharepoint Online Python Connector Improper Access Control
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46666?
CVE-2023-46666 is a vulnerability in Elastic Sharepoint Online Python Connector that allows users with limited access permissions to have read permissions to all content on the Sharepoint site.
How does CVE-2023-46666 affect Elastic Sharepoint Online Python Connector?
CVE-2023-46666 affects Elastic Sharepoint Online Python Connector when using Document Level Security and the SPO "Limited Access" functionality.
What is the severity of CVE-2023-46666?
The severity of CVE-2023-46666 is medium with a severity value of 6.5.
How can I fix CVE-2023-46666?
To fix CVE-2023-46666, upgrade Elastic Sharepoint Online Python Connector to version 8.10.3.0 or a later version.
Where can I find more information about CVE-2023-46666?
You can find more information about CVE-2023-46666 in the references provided: [Link 1](https://discuss.elastic.co/t/elastic-sharepoint-online-python-connector-v8-10-3-0-security-update/344732) and [Link 2](https://www.elastic.co/community/security).