CVE-2023-50292
published 2024-02-09CVE-2023-50292: Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.05%
86.1th percentile
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0.
The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets.
However, when the feature was created, the "trust" (authentication) of these configSets was not considered.
External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution.
Since the Schema Designer loaded configSets without taking their "trust" into account, configSets that were created by unauthenticated users were allowed to load external libraries when used in the Schema Designer.
Users are recommended to upgrade to version 9.3.0, which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | solr | >= 6.0.0 < 8.11.3 | 8.11.3 |
| apache | solr | >= 9.0.0 < 9.4.1 | 9.4.1 |
| apache_software_foundation | apache_solr | 8.10.0 – 8.11.2 | — |
| apache_software_foundation | apache_solr | >= 9.0.0 < 9.3.0 | 9.3.0 |
| debian | lucene-solr | < lucene-solr 3.6.2+dfsg-23 (bookworm) | lucene-solr 3.6.2+dfsg-23 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The Schema Designer feature in Apache Solr loads configSets without verifying their 'trust' status, allowing unauthenticated users to load external libraries and potentially achieve RCE. Monitor for unauthenticated requests to the Schema Designer endpoint that reference or load external libraries. ↗
- →Focus detection on Apache Solr versions 8.10.0 through 8.11.2 and 9.0.0 through 9.2.x, as these are the affected version ranges where the Schema Designer trust bypass is present. ↗
- →Alert on unauthenticated users interacting with the Schema Designer feature, particularly any activity that results in external library loading, as this is the exploitation path for RCE. ↗
- ·The vulnerability is only exploitable when the Schema Designer feature is accessible. Environments where Schema Designer is disabled or access is restricted mitigate the risk. ↗
- ·External library loading (the RCE vector) is gated on configSet 'trust'. The flaw is that Schema Designer bypasses this trust check, so the attack surface is specifically the Schema Designer code path, not general Solr configSet handling. ↗
- ·Red Hat Data Grid 8, Red Hat Integration Camel K 1, and Red Hat JBoss EAP 8 are listed as Not Affected. Red Hat Fuse 7 is 'Will not fix'. Tailor detection scope accordingly for these platforms. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-50292: Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr
osv·2024-02-09·CVSS 7.5
CVE-2023-50292 [HIGH] CVE-2023-50292: Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets. However, when the feature was created, the "trust" (authentication) of these configSets was not considered. External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution. Since the Schema Designer loaded configSets without taking their "trust" into account, configSets that were created by unauthenticated users were allowed to load external
GHSA
Apache Solr Schema Designer blindly "trusts" all configsets
ghsa·2024-02-09
CVE-2023-50292 [LOW] CWE-732 Apache Solr Schema Designer blindly "trusts" all configsets
Apache Solr Schema Designer blindly "trusts" all configsets
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This issue affects Apache Solr from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0.
The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets.
However, when the feature was created, the "trust" (authentication) of these configSets was not considered.
External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution.
Since the Schema Designer loaded configSets without taking their "trust" into account, configSets that were c
OSV
Apache Solr Schema Designer blindly "trusts" all configsets
osv·2024-02-09
CVE-2023-50292 [LOW] Apache Solr Schema Designer blindly "trusts" all configsets
Apache Solr Schema Designer blindly "trusts" all configsets
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This issue affects Apache Solr from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0.
The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets.
However, when the feature was created, the "trust" (authentication) of these configSets was not considered.
External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution.
Since the Schema Designer loaded configSets without taking their "trust" into account, configSets that were c
Red Hat
Solr: Schema Designer trusts all configsets, possibly leading to RCE by unauthenticated users
vendor_redhat·2024-02-09·CVSS 7.5
CVE-2023-50292 [HIGH] CWE-732 Solr: Schema Designer trusts all configsets, possibly leading to RCE by unauthenticated users
Solr: Schema Designer trusts all configsets, possibly leading to RCE by unauthenticated users
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0.
The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets.
However, when the feature was created, the "trust" (authentication) of these configSets was not considered.
External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution.
Since the Schema Designer loaded configSets without taking their "trust" int
Debian
CVE-2023-50292: lucene-solr - Incorrect Permission Assignment for Critical Resource, Improper Control of Dynam...
vendor_debian·2023·CVSS 7.5
CVE-2023-50292 [HIGH] CVE-2023-50292: lucene-solr - Incorrect Permission Assignment for Critical Resource, Improper Control of Dynam...
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets. However, when the feature was created, the "trust" (authentication) of these configSets was not considered. External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution. Since the Schema Designer loaded configSets without taking their "trust" into account, configSets that were created by unauthenticated users were allowed to load external
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/02/09/3https://solr.apache.org/security.html#cve-2023-50298-apache-solr-can-expose-zookeeper-credentials-via-streaming-expressionshttp://www.openwall.com/lists/oss-security/2024/02/09/3https://solr.apache.org/security.html#cve-2023-50298-apache-solr-can-expose-zookeeper-credentials-via-streaming-expressions
2024-02-09
Published