cbcvebase.
CVE-2023-50292
published 2024-02-09

CVE-2023-50292: Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects…

PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.05%
86.1th percentile
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets. However, when the feature was created, the "trust" (authentication) of these configSets was not considered. External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution. Since the Schema Designer loaded configSets without taking their "trust" into account, configSets that were created by unauthenticated users were allowed to load external libraries when used in the Schema Designer. Users are recommended to upgrade to version 9.3.0, which fixes the issue.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachesolr>= 6.0.0 < 8.11.38.11.3
apachesolr>= 9.0.0 < 9.4.19.4.1
apache_software_foundationapache_solr8.10.0 – 8.11.2
apache_software_foundationapache_solr>= 9.0.0 < 9.3.09.3.0
debianlucene-solr< lucene-solr 3.6.2+dfsg-23 (bookworm)lucene-solr 3.6.2+dfsg-23 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The Schema Designer feature in Apache Solr loads configSets without verifying their 'trust' status, allowing unauthenticated users to load external libraries and potentially achieve RCE. Monitor for unauthenticated requests to the Schema Designer endpoint that reference or load external libraries.
  • Focus detection on Apache Solr versions 8.10.0 through 8.11.2 and 9.0.0 through 9.2.x, as these are the affected version ranges where the Schema Designer trust bypass is present.
  • Alert on unauthenticated users interacting with the Schema Designer feature, particularly any activity that results in external library loading, as this is the exploitation path for RCE.
  • ·The vulnerability is only exploitable when the Schema Designer feature is accessible. Environments where Schema Designer is disabled or access is restricted mitigate the risk.
  • ·External library loading (the RCE vector) is gated on configSet 'trust'. The flaw is that Schema Designer bypasses this trust check, so the attack surface is specifically the Schema Designer code path, not general Solr configSet handling.
  • ·Red Hat Data Grid 8, Red Hat Integration Camel K 1, and Red Hat JBoss EAP 8 are listed as Not Affected. Red Hat Fuse 7 is 'Will not fix'. Tailor detection scope accordingly for these platforms.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.