PT-2024-2360 · Apache · Apache Solr

Skay

·

Published

2024-02-09

·

Updated

2024-03-06

·

CVE-2023-50292

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Solr versions 8.10.0 through 8.11.2 Apache Solr versions 9.0.0 through 9.2.x
Description The issue is related to an Incorrect Permission Assignment for Critical Resource and Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. The Schema Designer feature was introduced to allow users to more easily configure and test new Schemas and configSets. However, when the feature was created, the "trust" (authentication) of these configSets was not considered, allowing configSets created by unauthenticated users to load external libraries when used in the Schema Designer. This could potentially lead to Remote Code Execution.
Recommendations For Apache Solr versions 8.10.0 through 8.11.2, upgrade to version 8.11.3. For Apache Solr versions 9.0.0 through 9.2.x, upgrade to version 9.3.0.

Fix

RCE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02308
BIT-SOLR-2023-50292
CVE-2023-50292
GHSA-4WXW-42WX-2WFX

Affected Products

Apache Solr