Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j346-h5wc-rw2m

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Incorrect Authorization in Apache Solr

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 6.6.6 and 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

Пакеты

Наименование

org.apache.solr:solr-parent

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.7.0

7.7.0

Наименование

org.apache.solr:solr-parent

maven
Затронутые версииВерсия исправления

< 6.6.6

6.6.6

Наименование

org.apache.solr:solr-core

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.7.0

7.7.0

Наименование

org.apache.solr:solr-core

maven
Затронутые версииВерсия исправления

< 6.6.6

6.6.6

EPSS

Процентиль: 36%
0.00151
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 6 лет назад

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

CVSS3: 4.3
redhat
почти 7 лет назад

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

CVSS3: 4.3
nvd
почти 6 лет назад

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

CVSS3: 4.3
debian
почти 6 лет назад

In Apache Solr, the cluster can be partitioned into multiple collectio ...

EPSS

Процентиль: 36%
0.00151
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863