CRITICAL9.8CVE-2024-45216Apache Solr: Authentication bypass possible using a fake URL Path ending >= 5.3.0, < 8.11.4, >= 9.0.0, < 9.7.0
>= 6.6.0, < 6.6.7, >= 7.0.0, < 7.7.4, >= 8.0.0, < 8.6.3
CRITICAL9.8CVE-2021-44548Apache Solr information disclosure vulnerability through DataImportHandler from 0, < 8.11.1
CRITICAL9.1Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections
from 0, < 8.8.2
HIGH8.8Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
>= 6.0.0, < 8.11.3, >= 9.0.0, < 9.4.1
HIGH8.8Improper Input Validation in Apache Solr
from 0, < 8.6.0
HIGH8.8Improper Privilege Management in Apache Hadoop
>= 8.6.0, < 8.6.1, >= 8.6.2, < 8.6.3
HIGH8.2Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
>= 5.3.0, < 9.10.1
HIGH8.1Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
>= 9.4.0, < 10.0.0 | >= 10.0.0, <= 10.0.0
HIGH8.1Apache Solr: ConfigSets created during a backup restore command are trusted implicitly
>= 6.6.0, < 8.11.4, >= 9.0.0, < 9.7.0
HIGH7.5Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords
>= 6.0.0, < 8.11.3, >= 9.0.0, < 9.3.0
HIGH7.5Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users
>= 6.0.0, < 8.11.3, >= 9.0.0, < 9.4.1
HIGH7.5Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions
>= 6.0.0, < 8.11.3, >= 9.0.0, < 9.4.1
HIGH7.5libjdom1-java - security update
>= 8.8.1, < 8.8.2, >= 8.9.0, < 8.9.1
HIGH7.5Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings
from 0, < 8.8.2
HIGH7.1Apache Solr: Insufficient file-access checking in standalone core-creation requests
>= 8.6.0, < 9.10.1
HIGH7.1SSRF vulnerability with the Replication handler
from 0, < 8.8.2
MEDIUM6.5Apache Solr: Host environment variables are published via the Metrics API
>= 9.0.0, < 9.3.0
MEDIUM5.5Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files
from 0, < 9.8.0
MEDIUM5.4Apache Solr: Configset upload on Windows allows arbitrary path write-access
>= 6.6.0, < 9.8.0