CVE-2025-12147
Last modified
CVE-2025-12147 is a medium-severity vulnerability rated 6/10 on the CVSS scale. In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclusion rule (e.g., ~field) is applied to a field which contains an object as its value, the object is correctly removed from the _source returned by search operations. However, the object members (i.e., child attributes) remain accessible to search queries. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclusion rule (e.g., ~field) is applied to a field which contains an object as its value, the object is correctly removed from the _source returned by search operations. However, the object members (i.e., child attributes) remain accessible to search queries. This exposure allows adversaries to infer or reconstruct the original contents of the excluded object. Workaround - If you cannot upgrade immediately and FLS exclusion rules are used for object valued attributes (like ~object), add an additional exclusion rule for the members of the object (like ~object.*).
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-12147?
How severe is CVE-2025-12147?
How do I fix CVE-2025-12147?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12139The File Manager for Google Drive – Integrate Google Drive w…7.5
- CVE-2025-1214A vulnerability classified as critical has been found in pih…8.8
- CVE-2025-12140The application contains an insecure 'redirectToUrl' mechani…9.3
- CVE-2025-12141In Grafana's alerting system, users with edit permissions fo…6.5
- CVE-2025-12142Buffer Copy without Checking Size of Input ('Classic Buffer …6.9
- CVE-2025-12143Stack-based Buffer Overflow vulnerability in ABB Terra AC wa…6.9
- CVE-2025-12148In Search Guard versions 3.1.1 and earlier, Field Masking (F…6
- CVE-2025-12149In Search Guard FLX versions 3.1.2 and earlier, while Docume…6
- CVE-2025-1215A vulnerability classified as problematic was found in vim u…7.8
- CVE-2025-12150A flaw was found in Keycloak’s WebAuthn registration compone…3.1
- CVE-2025-12151The Simple Folio plugin for WordPress is vulnerable to Store…6.4
- CVE-2025-12152Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
Are you affected by CVE-2025-12147?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
