PT-2019-13542 · Alfresco+1 · Alfresco Community Edition+1

Drunkenshells

·

Published

2019-09-05

·

Updated

2021-07-21

·

CVE-2019-14222

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alfresco Community Edition versions 6.0 and lower
Description An issue allows an unauthenticated, remote attacker to authenticate to Alfresco's Solr Web Admin Interface. This is due to a default private key present in all default installations. An attacker could exploit this by using the extracted private key and bundling it into a PKCS12, potentially gaining information about the target system, such as OS type, system file locations, Java version, and Solr version. This access could also be leveraged to launch further attacks.
Recommendations For Alfresco Community Edition versions 6.0 and lower, consider removing or replacing the default private key to prevent unauthorized access to Alfresco's Solr Web Admin Interface. As a temporary workaround, restrict access to the Solr Web Admin Interface until a more permanent solution can be implemented.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14222

Affected Products

Alfresco Community Edition
Solr