GHSA-3c7p-vv5r-cmr5

Suggest an improvement
Source
https://github.com/advisories/GHSA-3c7p-vv5r-cmr5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-3c7p-vv5r-cmr5/GHSA-3c7p-vv5r-cmr5.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-3c7p-vv5r-cmr5
Aliases
Published
2022-02-10T00:31:27Z
Modified
2024-03-15T05:21:14.295800Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Incorrect Authorization in Apache Solr
Details

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions. This issue is patched in 8.6.3.

Database specific
{
    "nvd_published_at": "2020-10-13T19:15:00Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2021-04-14T17:55:51Z"
}
References

Affected packages

Maven / org.apache.solr:solr-parent

Package

Name
org.apache.solr:solr-parent
View open source insights on deps.dev
Purl
pkg:maven/org.apache.solr/solr-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
8.6.3

Affected versions

6.*

6.6.0
6.6.1
6.6.2
6.6.3
6.6.4
6.6.5
6.6.6

7.*

7.0.0
7.0.1
7.1.0
7.2.0
7.2.1
7.3.0
7.3.1
7.4.0
7.5.0
7.6.0
7.7.0
7.7.1
7.7.2
7.7.3

8.*

8.0.0
8.1.0
8.1.1
8.2.0
8.3.0
8.3.1
8.4.0
8.4.1
8.5.0
8.5.1
8.5.2
8.6.0
8.6.1
8.6.2