PT-2021-18153 · Apache · Apache Solr
Nit0906
·
Published
2021-04-13
·
Updated
2024-03-06
·
CVE-2021-29262
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Solr versions prior to 8.8.2
Description:
The issue arises when Apache Solr is started with specific configurations, such as the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider, and there is no existing security.json znode. If an optional read-only user is configured, Solr fails to treat the node as a sensitive path, allowing it to be readable. Furthermore, with any ZkACLProvider, if the security.json is already present, Solr does not automatically update the ACLs.
Recommendations:
For versions prior to 8.8.2, update to version 8.8.2 or later to resolve the issue. As a temporary workaround, consider manually configuring the ACLs for the security.json znode to ensure proper access control. Additionally, restrict access to sensitive paths until the update is applied.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Solr