First published: Wed Feb 07 2024(Updated: )
An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Network Drive Connector | <8.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23447 has been rated with a high severity due to improper permission handling leading to potential data exposure.
To fix CVE-2024-23447, update the Elastic Network Drive Connector to version 8.12.1 or later where the vulnerability is addressed.
CVE-2024-23447 affects the Elastic Network Drive Connector versions prior to 8.12.1.
If CVE-2024-23447 is not addressed, sensitive documents may be visible in search applications, posing a risk of unauthorized access.
There is currently no documented workaround for CVE-2024-23447; it is recommended to apply the available security update as soon as possible.