Skip to content
Apache SolrGHSA-3c7p-vv5r-cmr5

Incorrect Authorization in Apache Solr

Critical9.8CVE-2020-13957 · Published Feb 10, 2022 · updated Mar 17, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 6.6.0, < 8.6.38.6.3
Details and references

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions. This issue is patched in 8.6.3.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-solr-2020-13957, CVE-2020-13957

More Apache Solr advisories

All Apache Solr
DateAdvisory
Feb 92022Incorrect Authorization in Apache Solr
CVE-2018-11802Medium4.3fixed in 6.6.6, 7.7.0
May 142022Apache Solr Kerberos delegation token functionality flaws
CVE-2017-9803High7.5fixed in 6.6.1
May 142022Apache Solr insecure inter-node communication
CVE-2017-7660High7.5fixed in 5.5.5, 6.6.0
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8797Medium6.1fixed in 5.3.1
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8795Medium6.1fixed in 5.1.0
May 172022Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
CVE-2013-6397Mediumfixed in 4.6.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.