In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address).
While the content of these fields is properly redacted in the _source document returned by search operations, the results do return documents (hits) when searching based on a specific IP values. This allows to reconstruct the original contents of the field.
Workaround - If you cannot upgrade immediately, you can avoid the problem by using field level security (FLS) protection on fields of the affected types instead of field masking.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Search-guard
Search-guard search Guard |
|
| Vendors & Products |
Search-guard
Search-guard search Guard |
Wed, 29 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of these fields is properly redacted in the _source document returned by search operations, the results do return documents (hits) when searching based on a specific IP values. This allows to reconstruct the original contents of the field. Workaround - If you cannot upgrade immediately, you can avoid the problem by using field level security (FLS) protection on fields of the affected types instead of field masking. | |
| Title | Unauthorized access to fields protected by Field Masking (FM) for fields of type IP | |
| Weaknesses | CWE-200 CWE-732 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: floragunn
Published: 2025-10-29T15:31:32.419Z
Updated: 2025-10-29T16:11:51.396Z
Reserved: 2025-10-24T11:00:54.862Z
Link: CVE-2025-12148
Updated: 2025-10-29T16:11:15.835Z
Status : Awaiting Analysis
Published: 2025-10-29T16:15:33.743
Modified: 2025-10-30T15:03:13.440
Link: CVE-2025-12148
No data.
ReportizFlow