Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3c7p-vv5r-cmr5

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Incorrect Authorization in Apache Solr

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions. This issue is patched in 8.6.3.

Ссылки

Пакеты

Наименование

org.apache.solr:solr-parent

maven
Затронутые версииВерсия исправления

>= 6.6.0, < 8.6.3

8.6.3

Наименование

org.apache.solr:solr-solrj

maven
Затронутые версииВерсия исправления

>= 6.6.0, < 8.6.3

8.6.3

Наименование

org.apache.solr:solr-core

maven
Затронутые версииВерсия исправления

>= 6.6.0, < 8.6.3

8.6.3

EPSS

Процентиль: 99%
0.84821
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

CVSS3: 9.8
redhat
больше 5 лет назад

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

CVSS3: 9.8
nvd
больше 5 лет назад

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

CVSS3: 9.8
debian
больше 5 лет назад

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 ...

EPSS

Процентиль: 99%
0.84821
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-863