# Kibana 8.12.1 Security Update (ESA-2024-01)

**URL:** <https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-01/352686>\
**Category:** Security Announcements\
**Created:** [February 6, 2024, 10:13pm UTC](https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-01/352686 "2024-02-06T22:13:13Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodrigo\_silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rodrigo_silva/32/120546_2.png) [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Post date:** [February 6, 2024, 10:13pm UTC](https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-01/352686/1 "2024-02-06T22:13:13Z")

</div>

**Kibana Broken Access Control issue (ESA-2024-01)**

An issue was discovered by Elastic, whereby the Detection Engine Search [API](https://www.elastic.co/guide/en/security/current/signals-api-overview.html) does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space\_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.

**Affected Versions:**  
Kibana 8.x versions prior to 8.12.1

**Affected Configurations:**  
This issue only affects users that have assigned a role with DLS or FLS configured, users using KPI or group by feature on the alerts page or API users accessing the route directly.

**Solutions and Mitigations:**  
The issue is resolved in version 8.12.1

**Severity:** CVSSv3: 6.5 (Medium) - [AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N&version=3.1)

**CVE ID:** CVE-2024-23446
