Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27905

Опубликовано: 12 апр. 2021
Источник: redhat
CVSS3: 8.1

Описание

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

A flaw was found in solr. The ReplicationHandler in Apache Solr does not check proper parameters when connecting to another Solr instance to replicate index data into the local core leading to a SSRF vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Меры по смягчению последствий

Restrict access to the replication handler to only internal Solr instances.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7solrNot affected
Red Hat Integration Camel K 1camel-solrNot affected
Red Hat JBoss Data Virtualization 6solrOut of support scope
Red Hat JBoss Enterprise Application Platform 6solrOut of support scope
Red Hat JBoss Fuse 6solrOut of support scope
Red Hat JBoss Fuse Service Works 6solrOut of support scope
Red Hat JBoss Web Server 3solrNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=1949516solr: SSRF vulnerability with the Replication handler

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

CVSS3: 9.8
nvd
почти 5 лет назад

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

CVSS3: 9.8
debian
почти 5 лет назад

The ReplicationHandler (normally registered at "/replication" under a ...

CVSS3: 7.1
github
больше 4 лет назад

Server-Side Request Forgery in Apache Solr

8.1 High

CVSS3