Incorrect Authorization in Apache Solr
Critical severity
GitHub Reviewed
Published
Feb 10, 2022
to the GitHub Advisory Database
•
Updated Feb 16, 2023
Package
Affected versions
>= 6.6.0, < 8.6.3
Patched versions
8.6.3
Description
Published by the National Vulnerability Database
Oct 13, 2020
Reviewed
Apr 14, 2021
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Feb 16, 2023
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions. This issue is patched in 8.6.3.
References