Skip to content
Apache SolrGHSA-c82r-qg3w-q5mv

Apache Solr insecure inter-node communication

High7.5CVE-2017-7660 · Published May 14, 2022 · updated Feb 22, 2024

Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the nodes in cluster to believe that the malicious node is a member of the cluster. So, if Solr users have enabled BasicAuth authentication mechanism using the BasicAuthPlugin or if the user has implemented a custom Authentication plugin, which does not implement either "HttpClientInterceptorPlugin" or "HttpClientBuilderPlugin", his/her servers are vulnerable to this attack. Users who only use SSL without basic authentication or those who use Kerberos are not affected.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 5.3.0, < 5.5.55.5.5
>= 6.0.0, < 6.6.06.6.0
Details and references

More Apache Solr advisories

All Apache Solr
Advisory
Apache Solr UpdateRequestHandler for XML resolves XML External Entities
MediumMay 17, 2022
XML Injection in Apache Solr
MediumMay 17, 2022
Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
MediumMay 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022
Apache Solr Kerberos delegation token functionality flaws
High7.5May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.