Логотип exploitDog
bind:CVE-2024-45216
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45216

Количество 5

Количество 5

ubuntu логотип

CVE-2024-45216

больше 1 года назад

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2024-45216

больше 1 года назад

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2024-45216

больше 1 года назад

Improper Authentication vulnerability in Apache Solr. Solr instances ...

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-mjvf-4h88-6xm3

больше 1 года назад

Improper Authentication vulnerability in Apache Solr

CVSS3: 9.8
EPSS: Критический
fstec логотип

BDU:2024-08828

больше 1 года назад

Уязвимость плагина PKIAuthenticationPlugin поискового сервера Apache Solr, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-45216

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.

CVSS3: 9.8
94%
Критический
больше 1 года назад
nvd логотип
CVE-2024-45216

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.

CVSS3: 9.8
94%
Критический
больше 1 года назад
debian логотип
CVE-2024-45216

Improper Authentication vulnerability in Apache Solr. Solr instances ...

CVSS3: 9.8
94%
Критический
больше 1 года назад
github логотип
GHSA-mjvf-4h88-6xm3

Improper Authentication vulnerability in Apache Solr

CVSS3: 9.8
94%
Критический
больше 1 года назад
fstec логотип
BDU:2024-08828

Уязвимость плагина PKIAuthenticationPlugin поискового сервера Apache Solr, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
94%
Критический
больше 1 года назад

Уязвимостей на страницу