CVE Vulnerabilities

CVE-2023-46666

Published: Oct 26, 2023 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered when using Document Level Security and the SPO Limited Access functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.

Affected Software

Name Vendor Start Version End Version
Elastic_sharepoint_online_python_connector Elastic * 8.10.3.0 (excluding)

References