Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf7p-j8x6-xvwp

Опубликовано: 10 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Incorrect Authorization in Apache Solr

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.

Пакеты

Наименование

org.apache.solr:solr-parent

maven
Затронутые версииВерсия исправления

< 8.8.2

8.8.2

EPSS

Процентиль: 92%
0.07673
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 5 лет назад

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.

CVSS3: 9.1
redhat
почти 5 лет назад

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.

CVSS3: 9.1
nvd
почти 5 лет назад

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.

CVSS3: 9.1
debian
почти 5 лет назад

When using ConfigurableInternodeAuthHadoopPlugin for authentication, A ...

EPSS

Процентиль: 92%
0.07673
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-863