Skip to content
Apache SolrGHSA-j346-h5wc-rw2m

Incorrect Authorization in Apache Solr

Medium4.3CVE-2018-11802 · Published Feb 9, 2022 · updated Nov 10, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 7.0.0, < 7.7.07.7.0
< 6.6.66.6.6
Details and references

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 6.6.6 and 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
CVE-2018-11802

More Apache Solr advisories

All Apache Solr
DateAdvisory
Feb 102022Incorrect Authorization in Apache Solr
CVE-2020-13957Critical9.8fixed in 8.6.3
May 142022Apache Solr Kerberos delegation token functionality flaws
CVE-2017-9803High7.5fixed in 6.6.1
May 142022Apache Solr insecure inter-node communication
CVE-2017-7660High7.5fixed in 5.5.5, 6.6.0
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8797Medium6.1fixed in 5.3.1
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8795Medium6.1fixed in 5.1.0
May 172022Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
CVE-2013-6397Mediumfixed in 4.6.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.