Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xrj7-x7gp-wwqr

Опубликовано: 09 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.5

Описание

Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. This issue affects Apache Solr from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.

Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter.

When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides.

An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost".

Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions.

Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue.

From these versions on, only zkHost values that have the same server address (regardless of chroot), will use the given ZooKeeper credentials and ACLs when connecting.

Пакеты

Наименование

org.apache.solr:solr-solrj-streaming

maven
Затронутые версииВерсия исправления

>= 9.0.0, < 9.4.1

9.4.1

Наименование

org.apache.solr:solr-solrj-streaming

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 8.11.3

8.11.3

Наименование

org.apache.solr:solr-solrj

maven
Затронутые версииВерсия исправления

>= 9.0.0, < 9.4.1

9.4.1

Наименование

org.apache.solr:solr-solrj

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 8.11.3

8.11.3

EPSS

Процентиль: 14%
0.00045
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-922

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter. When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides. An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost". Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue. From these versions on, only zkHost values that have the same server address (regardless of chroot), will use the given ZooKeeper credentials and ACLs when connecting.

CVSS3: 7.5
redhat
около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter. When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides. An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost". Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue. From these versions on, only zkHost values that have the same server address (regardless of chroot), will use the given ZooKeeper credentials and ACLs when connecting.

CVSS3: 7.5
nvd
почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter. When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides. An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost". Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue. From these versions on, only zkHost values that have the same server address (regardless of chroot), will use the given ZooKeeper credentials and ACLs when connecting.

CVSS3: 7.5
debian
почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость поискового сервера Apache Solr, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 14%
0.00045
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-922