CVE-2018-11802
Incorrect Authorization in Apache Solr
4.3
MEDIUM
CVSS 3.1
EPSS 2.0%
描述
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 6.6.6 and 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
如何修補 CVE-2018-11802
要修補 CVE-2018-11802,請將受影響套件升級到下列已修補版本。
- —升級至 7.7.0 或更新版本
- —升級至 7.7.0 或更新版本
CVE-2018-11802 正在被利用嗎?
低 — EPSS 為 2.0%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 7.0.0, < 7.7.0
- >= 7.0.0, < 7.7.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |