CVE-2018-11802
published 2020-04-01CVE-2018-11802: In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
2.02%
78.9th percentile
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_solr | — | — |
| apache | solr | >= 4.2.0 < 6.6.6 | 6.6.6 |
| apache | solr | >= 7.0.0 < 7.7.0 | 7.7.0 |
| debian | lucene-solr | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
solr: Information disclosure via Rule-base Authorization plugin
vendor_redhat·2019-04-24·CVSS 4.3
CVE-2018-11802 [MEDIUM] CWE-200 solr: Information disclosure via Rule-base Authorization plugin
solr: Information disclosure via Rule-base Authorization plugin
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
Statement: Red Hat Fuse 7 includes camel-solr to allow interfacing with Apache Lucene Solr clusters. This is only a client interface and is not affected by this vulnerability.
Package: solr (JBoss Developer Studio 11) - Out of support scope
Package: camel-solr (Red Ha
Debian
CVE-2018-11802: lucene-solr - In Apache Solr, the cluster can be partitioned into multiple collections and onl...
vendor_debian·2018·CVSS 4.3
CVE-2018-11802 [MEDIUM] CVE-2018-11802: lucene-solr - In Apache Solr, the cluster can be partitioned into multiple collections and onl...
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Incorrect Authorization in Apache Solr
osv·2022-02-09
CVE-2018-11802 [MEDIUM] Incorrect Authorization in Apache Solr
Incorrect Authorization in Apache Solr
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 6.6.6 and 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
GHSA
Incorrect Authorization in Apache Solr
ghsa·2022-02-09
CVE-2018-11802 [MEDIUM] CWE-863 Incorrect Authorization in Apache Solr
Incorrect Authorization in Apache Solr
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 6.6.6 and 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
OSV
CVE-2018-11802: In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection
osv·2020-04-01·CVSS 4.3
CVE-2018-11802 [MEDIUM] CVE-2018-11802: In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11802 solr: Information disclosure via Rule-base Authorization plugin
bugzilla·2019-05-07·CVSS 4.3
CVE-2018-11802 [MEDIUM] CVE-2018-11802 solr: Information disclosure via Rule-base Authorization plugin
CVE-2018-11802 solr: Information disclosure via Rule-base Authorization plugin
In apache Solr the cluster can be partitioned into multiple
collections and only a subset of nodes actually host any given
collection. However, if a node receives a request for a collection it
does not host, it proxies the request to a relevant node and serves
the request. Solr bypasses all authorization settings for such
requests. This affects all Solr versions that uses the default
authorization mechanism of Solr (RuleBasedAuthorizationPlugin)
Upstream bug:
https://issues.apache.org/jira/browse/SOLR-12514
References:
https://www.openwall.com/lists/oss-security/2019/04/24/1
Discussion:
Created solr3 tracking bugs for this issue:
Affects: fedora-all [bug 1707548]
---
This vulnerability is out of securi
Bugzilla
CVE-2018-11802 solr3: solr: Information disclosure via Rule-base Authorization plugin [fedora-all]
bugzilla·2019-05-07·CVSS 4.3
CVE-2018-11802 [MEDIUM] CVE-2018-11802 solr3: solr: Information disclosure via Rule-base Authorization plugin [fedora-all]
CVE-2018-11802 solr3: solr: Information disclosure via Rule-base Authorization plugin [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
2020-04-01
Published