solr: Information disclosure via Rule-base Authorization plugin
Published Apr 1, 2020
4.3
MEDIUMCVSS 3.1
EPSS 2.02%
Description
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
Affected products
-
- Version before 7.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache | Apache Solr | n/a |
|
No data.
JBoss Developer Studio 11
solr
Out of support scope
Red Hat Fuse 7
camel-solr
Not affected
Red Hat JBoss Data Grid 6
solr-core
Out of support scope
Red Hat JBoss Data Virtualization 6
solr-core
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
solr-core
Out of support scope
Red Hat JBoss Fuse 6
solr-core
Out of support scope
Red Hat JBoss Fuse Service Works 6
solr-core
Out of support scope
Red Hat Virtualization 4
rhvm-appliance
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Developer Studio 11 | solr | Out of support scope | n/a |
| Red Hat Fuse 7 | camel-solr | Not affected | n/a |
| Red Hat JBoss Data Grid 6 | solr-core | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | solr-core | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | solr-core | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | solr-core | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | solr-core | Out of support scope | n/a |
| Red Hat Virtualization 4 | rhvm-appliance | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Fuse 7 includes camel-solr to allow interfacing with Apache Lucene Solr clusters. This is only a client interface and is not affected by this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.02% (0.02020) | 80.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.02% (0.02020) | 78.34th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.17% (0.00165) | 35.12th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00066) | 31.05th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.07% (0.00066) | 28.85th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00066) | 26.85th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.24% (0.01241) | 30.13th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.24% (0.01241) | 0.00th | v1 |
References (8)
- https://access.redhat.com/security/cve/CVE-2018-11802 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1707547 Issue Tracking
- https://github.com/advisories/GHSA-j346-h5wc-rw2m Advisory
- https://github.com/apache/lucene-solr/commit/add003f217806afb4e1604f697cdb0a5a7115895
- https://issues.apache.org/jira/browse/SOLR-12514
- https://nvd.nist.gov/vuln/detail/CVE-2018-11802
- https://www.cve.org/CVERecord?id=CVE-2018-11802
- https://www.openwall.com/lists/oss-security/2019/04/24/1 x_refsource_MISCMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-11802 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1707547 | Issue Tracking | |
| https://github.com/advisories/GHSA-j346-h5wc-rw2m | Advisory | |
| https://github.com/apache/lucene-solr/commit/add003f217806afb4e1604f697cdb0a5a7115895 | ||
| https://issues.apache.org/jira/browse/SOLR-12514 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-11802 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-11802 | ||
| https://www.openwall.com/lists/oss-security/2019/04/24/1 | x_refsource_MISCMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.