
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Solr versions prior to 7.7 contain an authorization bypass vulnerability (CVE-2018-11802). In Apache Solr clusters, which can be partitioned into multiple collections, nodes that receive requests for collections they don't host will proxy these requests to relevant nodes. The vulnerability exists because Solr bypasses all authorization settings for such proxied requests when using the default authorization mechanism (RuleBasedAuthorizationPlugin) (Openwall Advisory).
The vulnerability has been assigned a CVSS v3.1 Base Score of 4.3 (MEDIUM) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. The vulnerability is classified as CWE-863 (Incorrect Authorization) and affects all versions of Apache Solr prior to version 7.7.0 (NVD Database).
The vulnerability allows unauthorized access to collection data through proxy requests, potentially exposing sensitive information to attackers who have network access to the Solr cluster (NVD Database).
Users are advised to upgrade to Solr version 7.7 or later, which contains the fix for this vulnerability. This is particularly important for installations using Solr's default authorization mechanism (RuleBasedAuthorizationPlugin) (Openwall Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."