Back

MEDIUM

solr: Information disclosure via Rule-base Authorization plugin

Published Apr 1, 2020

Description

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

Affected products

Remediation

Red Hat statement

Red Hat Fuse 7 includes camel-solr to allow interfacing with Apache Lucene Solr clusters. This is only a client interface and is not affected by this vulnerability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 1, 2020
Updated Aug 5, 2024
Reserved Jun 5, 2018
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 24, 2019
GHSA-J346-H5WC-RW2M