CVE-2018-11802
Incorrect Authorization in Apache Solr
4.3
MEDIUM
CVSS 3.1
EPSS 0.15%
Description
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 6.6.6 and 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
How to fix CVE-2018-11802
To remediate CVE-2018-11802, upgrade the affected package to a fixed version below.
- —upgrade to 7.7.0 or later
- —upgrade to 7.7.0 or later
Is CVE-2018-11802 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 7.0.0, < 7.7.0
- >= 7.0.0, < 7.7.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |