{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2024-23445","title":"Title"},{"category":"description","text":"It was identified that if a  cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body   restricts search for a given index using the query  or the field_security  parameter, and the same cross-cluster API key also grants replication for the same index, the search restrictions are not enforced during cross cluster search operations and search results may include documents and terms that should not be returned.\n\nThis issue only affects the  API key based security model for remote clusters https://www.elastic.co/guide/en/elasticsearch/reference/8.14/remote-clusters.html#remote-clusters-security-models   that was previously a beta feature and is released as GA with 8.14.0","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2024-23445","url":"https://www.suse.com/security/cve/CVE-2024-23445"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1226046 for CVE-2024-23445","url":"https://bugzilla.suse.com/1226046"}],"title":"SUSE CVE CVE-2024-23445","tracking":{"current_release_date":"2025-12-19T01:10:08Z","generator":{"date":"2025-02-14T05:27:44Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2024-23445","initial_release_date":"2025-02-14T05:27:44Z","revision_history":[{"date":"2025-02-14T05:27:44Z","number":"2","summary":"Current version"},{"date":"2025-02-16T05:20:41Z","number":"3","summary":"Current version"},{"date":"2025-03-15T05:32:05Z","number":"4","summary":"Current version"},{"date":"2025-04-24T14:54:37Z","number":"5","summary":"Current version"},{"date":"2025-12-17T01:01:28Z","number":"6","summary":"description changed"},{"date":"2025-12-19T01:10:08Z","number":"7","summary":"description changed"}],"status":"interim","version":"7"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"HPE Helion OpenStack 8","product":{"name":"HPE Helion OpenStack 8","product_id":"HPE Helion OpenStack 8","product_identification_helper":{"cpe":"cpe:/o:suse:hpe-helion-openstack:8"}}},{"category":"product_name","name":"SUSE OpenStack Cloud 8","product":{"name":"SUSE OpenStack Cloud 8","product_id":"SUSE OpenStack Cloud 8","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud:8"}}},{"category":"product_name","name":"SUSE OpenStack Cloud 9","product":{"name":"SUSE OpenStack Cloud 9","product_id":"SUSE OpenStack Cloud 9","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud:9"}}},{"category":"product_name","name":"SUSE OpenStack Cloud Crowbar 8","product":{"name":"SUSE OpenStack Cloud Crowbar 8","product_id":"SUSE OpenStack Cloud Crowbar 8","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud-crowbar:8"}}},{"category":"product_name","name":"SUSE OpenStack Cloud Crowbar 9","product":{"name":"SUSE OpenStack Cloud Crowbar 9","product_id":"SUSE OpenStack Cloud Crowbar 9","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud-crowbar:9"}}},{"category":"product_version","name":"elasticsearch","product":{"name":"elasticsearch","product_id":"elasticsearch","product_identification_helper":{"cpe":"cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/elasticsearch@?upstream=elasticsearch.src.rpm"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"elasticsearch as component of HPE Helion OpenStack 8","product_id":"HPE Helion OpenStack 8:elasticsearch"},"product_reference":"elasticsearch","relates_to_product_reference":"HPE Helion OpenStack 8"},{"category":"default_component_of","full_product_name":{"name":"elasticsearch as component of SUSE OpenStack Cloud 8","product_id":"SUSE OpenStack Cloud 8:elasticsearch"},"product_reference":"elasticsearch","relates_to_product_reference":"SUSE OpenStack Cloud 8"},{"category":"default_component_of","full_product_name":{"name":"elasticsearch as component of SUSE OpenStack Cloud 9","product_id":"SUSE OpenStack Cloud 9:elasticsearch"},"product_reference":"elasticsearch","relates_to_product_reference":"SUSE OpenStack Cloud 9"},{"category":"default_component_of","full_product_name":{"name":"elasticsearch as component of SUSE OpenStack Cloud Crowbar 8","product_id":"SUSE OpenStack Cloud Crowbar 8:elasticsearch"},"product_reference":"elasticsearch","relates_to_product_reference":"SUSE OpenStack Cloud Crowbar 8"},{"category":"default_component_of","full_product_name":{"name":"elasticsearch as component of SUSE OpenStack Cloud Crowbar 9","product_id":"SUSE OpenStack Cloud Crowbar 9:elasticsearch"},"product_reference":"elasticsearch","relates_to_product_reference":"SUSE OpenStack Cloud Crowbar 9"}]},"vulnerabilities":[{"cve":"CVE-2024-23445","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2024-23445"}],"notes":[{"category":"general","text":"It was identified that if a  cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body   restricts search for a given index using the query  or the field_security  parameter, and the same cross-cluster API key also grants replication for the same index, the search restrictions are not enforced during cross cluster search operations and search results may include documents and terms that should not be returned.\n\nThis issue only affects the  API key based security model for remote clusters https://www.elastic.co/guide/en/elasticsearch/reference/8.14/remote-clusters.html#remote-clusters-security-models   that was previously a beta feature and is released as GA with 8.14.0","title":"CVE description"}],"product_status":{"known_not_affected":["HPE Helion OpenStack 8:elasticsearch","SUSE OpenStack Cloud 8:elasticsearch","SUSE OpenStack Cloud 9:elasticsearch","SUSE OpenStack Cloud Crowbar 8:elasticsearch","SUSE OpenStack Cloud Crowbar 9:elasticsearch"]},"references":[{"category":"external","summary":"CVE-2024-23445","url":"https://www.suse.com/security/cve/CVE-2024-23445"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1226046 for CVE-2024-23445","url":"https://bugzilla.suse.com/1226046"}],"threats":[{"category":"impact","date":"2024-06-06T12:00:30Z","details":"moderate"}],"title":"CVE-2024-23445"}]}