Search Guard FLX
cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*
- >= 1.0.0, <= 4.0.1
A vulnerability exists in Search Guard FLX versions 1.0.0 prior to 4.0.1, where the audit logging feature may inadvertently log user credentials during login to Kibana. This issue could lead to unauthorized access to sensitive information.
Exposed user credentials in audit logs, potentially leading to unauthorized access.
Users can update to Search Guard FLX version 4.1.0 or disable request-body logging. To disable request-body logging globally, set 'searchguard.audit.log_request_body' to false. Alternatively, request bodies can be excluded for specific endpoints by adding them to 'searchguard.audit.ignore_request_bodies'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.