Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11802

Опубликовано: 24 апр. 2019
Источник: redhat
CVSS3: 4.3

Описание

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

Отчет

Red Hat Fuse 7 includes camel-solr to allow interfacing with Apache Lucene Solr clusters. This is only a client interface and is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11solrOut of support scope
Red Hat Fuse 7camel-solrNot affected
Red Hat JBoss Data Grid 6solr-coreOut of support scope
Red Hat JBoss Data Virtualization 6solr-coreOut of support scope
Red Hat JBoss Enterprise Application Platform 6solr-coreOut of support scope
Red Hat JBoss Fuse 6solr-coreOut of support scope
Red Hat JBoss Fuse Service Works 6solr-coreOut of support scope
Red Hat Virtualization 4rhvm-applianceNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1707547solr: Information disclosure via Rule-base Authorization plugin

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 6 лет назад

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

CVSS3: 4.3
nvd
почти 6 лет назад

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

CVSS3: 4.3
debian
почти 6 лет назад

In Apache Solr, the cluster can be partitioned into multiple collectio ...

CVSS3: 4.3
github
почти 4 года назад

Incorrect Authorization in Apache Solr

4.3 Medium

CVSS3