Fedora Account System
Red Hat Associate
Red Hat Customer
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database. References: https://docs.search-guard.com/6.x-23/changelog-searchguard-6-x-23_1 https://search-guard.com/cve-advisory/ https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SySS-2018-025.txt