Upstream information

CVE-2017-8450 at MITRE


X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.

SUSE information

SUSE Bugzilla entry: 1044849

No SUSE Security Announcements cross referenced.