Apache SolrGHSA-j346-h5wc-rw2m
Incorrect Authorization in Apache Solr
Medium4.3CVE-2018-11802 · Published Feb 9, 2022 · updated Nov 10, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.solr:solr-core Maven | >= 7.0.0, < 7.7.0 | 7.7.0 |
| < 6.6.6 | 6.6.6 |
Details and references
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 6.6.6 and 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- CVE-2018-11802
More Apache Solr advisories
All Apache Solr| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 102022 | Incorrect Authorization in Apache Solr CVE-2020-13957Critical9.8fixed in 8.6.3 | Critical9.8 | 8.6.3 |
| May 142022 | Apache Solr Kerberos delegation token functionality flaws CVE-2017-9803High7.5fixed in 6.6.1 | High7.5 | 6.6.1 |
| May 142022 | Apache Solr insecure inter-node communication CVE-2017-7660High7.5fixed in 5.5.5, 6.6.0 | High7.5 | 5.5.5, 6.6.0 |
| May 172022 | Improper Neutralization of Input During Web Page Generation in Apache Solr CVE-2015-8797Medium6.1fixed in 5.3.1 | Medium6.1 | 5.3.1 |
| May 172022 | Improper Neutralization of Input During Web Page Generation in Apache Solr CVE-2015-8795Medium6.1fixed in 5.1.0 | Medium6.1 | 5.1.0 |
| May 172022 | Improper Limitation of a Pathname to a Restricted Directory in Apache Solr CVE-2013-6397Mediumfixed in 4.6.0 | Medium | 4.6.0 |