CVE-2018-11802 – org.apache.solr:solr-parent
Package
Manager: maven
Name: org.apache.solr:solr-parent
Vulnerable Version: >=0 <7.7.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00151 pctl0.36235
Details
Incorrect Authorization in Apache Solr In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
Metadata
Created: 2022-02-09T23:19:26Z
Modified: 2022-02-09T23:19:26Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-j346-h5wc-rw2m/GHSA-j346-h5wc-rw2m.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-j346-h5wc-rw2m
Finding: F006
Auto approve: 1