CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It affects SharePoint.
CVE
CVE-2023-46666
Severity
MEDIUM
CVSS
5.3
EPSS
0.36%
SharePoint
Original NVD Description
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.
Related CVEs
Other vulnerabilities affecting the same vendor(s)