Security Advisory
CVE-2019-13421
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.