-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers on Document Level Security (DLS) bypass via improper authorization in query processing. Based on Elasticsearch's architecture:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.elasticsearch:elasticsearch | maven | >= 8.16.0, < 8.16.2 | 8.16.2 |
Ongoing coverage of React2Shell