CVE-2024-23447: Elastic Network Drive Connector Improper Access Control
An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23447?
CVE-2024-23447 has been rated with a high severity due to improper permission handling leading to potential data exposure.
How do I fix CVE-2024-23447?
To fix CVE-2024-23447, update the Elastic Network Drive Connector to version 8.12.1 or later where the vulnerability is addressed.
What systems are affected by CVE-2024-23447?
CVE-2024-23447 affects the Elastic Network Drive Connector versions prior to 8.12.1.
What are the potential risks if CVE-2024-23447 is not addressed?
If CVE-2024-23447 is not addressed, sensitive documents may be visible in search applications, posing a risk of unauthorized access.
Is there a workaround for CVE-2024-23447 until a fix can be applied?
There is currently no documented workaround for CVE-2024-23447; it is recommended to apply the available security update as soon as possible.