Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2467-h365-j7hm

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Input Validation in Apache Solr

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e you could read/write to any location the solr user can access.

Пакеты

Наименование

org.apache.solr:solr-parent

maven
Затронутые версииВерсия исправления

< 8.6.0

8.6.0

EPSS

Процентиль: 84%
0.02295
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 5 лет назад

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e you could read/write to any location the solr user can access.

CVSS3: 8.8
redhat
почти 5 лет назад

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e you could read/write to any location the solr user can access.

CVSS3: 8.8
nvd
почти 5 лет назад

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e you could read/write to any location the solr user can access.

CVSS3: 8.8
debian
почти 5 лет назад

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), rel ...

EPSS

Процентиль: 84%
0.02295
Низкий

8.8 High

CVSS3

Дефекты

CWE-20