# Elastic Network Drive Connector 8.12.1 Security Update (ESA-2024-02)

**URL:** <https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687>\
**Category:** Security Announcements\
**Created:** [February 6, 2024, 10:23pm UTC](https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687 "2024-02-06T22:23:09Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodrigo\_silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rodrigo_silva/32/120546_2.png) [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Post date:** [February 6, 2024, 10:23pm UTC](https://discuss.elastic.co/t/elastic-network-drive-connector-8-12-1-security-update-esa-2024-02/352687/1 "2024-02-06T22:23:10Z")

</div>

**Elastic Network Drive Connector Improper Access Control (ESA-2024-02)**

An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read.

Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.

**Affected Versions:**  
Elastic Network Drive Connector before 8.12.1.

**Solutions and Mitigations:**  
The issue is resolved in Elastic Network Drive Connector v8.12.1 and above

**CVSSv3:** 5.3 (Medium) - [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)

**CVE ID:** CVE-2024-23447
