SB2024070251 - Information disclosure in Elastic Network Drive Connector
Published: July 2, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2024-23447)
The vulnerability allows a remote user to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. A remote user can bypass implemented security restrictions and gain unauthorized access to sensitive information.
Remediation
Install update from vendor's website.