Skip to content
Apache SolrGHSA-jgcr-fg3g-qvw8

Improper permission handling in Apache Solr

High7.5CVE-2021-29262 · Published May 10, 2021 · updated Feb 17, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
< 8.8.28.8.2
Details and references

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-279, CWE-522
Also known as
BIT-solr-2021-29262, CVE-2021-29262

More Apache Solr advisories

All Apache Solr
DateAdvisory
Feb 92022Incorrect Authorization in Apache Solr
CVE-2018-11802Medium4.3fixed in 6.6.6, 7.7.0
Feb 102022Incorrect Authorization in Apache Solr
CVE-2020-13957Critical9.8fixed in 8.6.3
May 142022Apache Solr Kerberos delegation token functionality flaws
CVE-2017-9803High7.5fixed in 6.6.1
May 142022Apache Solr insecure inter-node communication
CVE-2017-7660High7.5fixed in 5.5.5, 6.6.0
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8797Medium6.1fixed in 5.3.1
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8795Medium6.1fixed in 5.1.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.