1 results (0.002 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch. Se descubrió un problema al utilizar la seguridad a nivel de documento y la funcionalidad de "acceso limitado" de SPO en Elastic Sharepoint Online Python Connector. Si a un usuario se le asignan permisos de acceso limitado a un elemento en un sitio de Sharepoint, ese usuario tendría permisos de lectura para todo el contenido del sitio de Sharepoint a través de Elasticsearch. • https://discuss.elastic.co/t/elastic-sharepoint-online-python-connector-v8-10-3-0-security-update/344732 https://www.elastic.co/community/security • CWE-284: Improper Access Control •