Логотип exploitDog
bind:CVE-2017-9803
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-9803

Количество 5

Количество 5

ubuntu логотип

CVE-2017-9803

больше 8 лет назад

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be leaked to users other than the solr super user. Secondly, malicious users can exploit this leaked configuration for privilege escalation to further expose/modify private data and/or disrupt operations in the Solr cluster. The vulnerability is fixed from Apache Solr 6.6.1 onwards.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-9803

больше 8 лет назад

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be leaked to users other than the solr super user. Secondly, malicious users can exploit this leaked configuration for privilege escalation to further expose/modify private data and/or disrupt operations in the Solr cluster. The vulnerability is fixed from Apache Solr 6.6.1 onwards.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2017-9803

больше 8 лет назад

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be leaked to users other than the solr super user. Secondly, malicious users can exploit this leaked configuration for privilege escalation to further expose/modify private data and/or disrupt operations in the Solr cluster. The vulnerability is fixed from Apache Solr 6.6.1 onwards.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-9803

больше 8 лет назад

Apache Solr's Kerberos plugin can be configured to use delegation toke ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f553-j2gv-g5r9

больше 3 лет назад

Apache Solr Kerberos delegation token functionality flaws

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be leaked to users other than the solr super user. Secondly, malicious users can exploit this leaked configuration for privilege escalation to further expose/modify private data and/or disrupt operations in the Solr cluster. The vulnerability is fixed from Apache Solr 6.6.1 onwards.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be leaked to users other than the solr super user. Secondly, malicious users can exploit this leaked configuration for privilege escalation to further expose/modify private data and/or disrupt operations in the Solr cluster. The vulnerability is fixed from Apache Solr 6.6.1 onwards.

CVSS3: 8.1
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be leaked to users other than the solr super user. Secondly, malicious users can exploit this leaked configuration for privilege escalation to further expose/modify private data and/or disrupt operations in the Solr cluster. The vulnerability is fixed from Apache Solr 6.6.1 onwards.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation toke ...

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
github логотип
GHSA-f553-j2gv-g5r9

Apache Solr Kerberos delegation token functionality flaws

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу