CVE-2021-29262

Insufficiently Protected Credentials in maven/org.apache.solr/solr-core

Identifier

CVE-2021-29262

Package Slug

maven/org.apache.solr/solr-core

Vulnerability

Insufficiently Protected Credentials

Description

When starting Apache Solr, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.

Affected Versions

All versions before 8.8.2

Solution

Upgrade to version 8.8.2 or above.

Last Modified

2021-04-21

source