CVE-2023-50298
published 2024-02-09CVE-2023-50298: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.56%
72.5th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.
Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter.
When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides.
An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information,
then send a streaming expression using the mock server's address in "zkHost".
Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions.
Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue.
From these versions on, only zkHost values that have the same server address (regardless of chroot), will use the given ZooKeeper credentials and ACLs when connecting.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | solr | >= 6.0.0 < 8.11.3 | 8.11.3 |
| apache | solr | >= 9.0.0 < 9.4.1 | 9.4.1 |
| apache_software_foundation | apache_solr | 6.0.0 – 8.11.2 | — |
| apache_software_foundation | apache_solr | >= 9.0.0 < 9.4.1 | 9.4.1 |
| debian | lucene-solr | < lucene-solr 3.6.2+dfsg-23 (bookworm) | lucene-solr 3.6.2+dfsg-23 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-50298: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr
osv·2024-02-09·CVSS 7.5
CVE-2023-50298 [HIGH] CVE-2023-50298: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter. When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides. An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost". Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix th
GHSA
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
ghsa·2024-02-09
CVE-2023-50298 [MEDIUM] CWE-200 Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. This issue affects Apache Solr from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.
Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter.
When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides.
An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost".
Streaming Expressions are exposed via the "/streaming" handler, with "
OSV
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
osv·2024-02-09
CVE-2023-50298 [MEDIUM] Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. This issue affects Apache Solr from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.
Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter.
When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides.
An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost".
Streaming Expressions are exposed via the "/streaming" handler, with "
Red Hat
solr: possible exposure of ZooKeeper credentials via Streaming Expressions
vendor_redhat·2024-02-09·CVSS 7.5
CVE-2023-50298 [HIGH] CWE-200 solr: possible exposure of ZooKeeper credentials via Streaming Expressions
solr: possible exposure of ZooKeeper credentials via Streaming Expressions
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.
Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter.
When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides.
An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information,
then send a streaming expression using the mock server's address in "zkHost".
Streaming Expressions are exposed via the "/streaming" handler, with "read" permission
Debian
CVE-2023-50298: lucene-solr - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac...
vendor_debian·2023·CVSS 7.5
CVE-2023-50298 [HIGH] CVE-2023-50298: lucene-solr - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac...
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter. When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides. An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost". Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix th
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-50292 Solr: Schema Designer trusts all configsets, possibly leading to RCE by unauthenticated users
bugzilla·2024-02-09·CVSS 7.5
CVE-2023-50292 [HIGH] CVE-2023-50292 Solr: Schema Designer trusts all configsets, possibly leading to RCE by unauthenticated users
CVE-2023-50292 Solr: Schema Designer trusts all configsets, possibly leading to RCE by unauthenticated users
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0.
The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets. However, when the feature was created, the "trust" (authentication) of these configSets was not considered. External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution. Since the Schema Designer loaded configSets without taking
Bugzilla
CVE-2023-50298 solr: possible exposure of ZooKeeper credentials via Streaming Expressions
bugzilla·2024-02-09·CVSS 7.5
CVE-2023-50298 [HIGH] CVE-2023-50298 solr: possible exposure of ZooKeeper credentials via Streaming Expressions
CVE-2023-50298 solr: possible exposure of ZooKeeper credentials via Streaming Expressions
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.
Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter. When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides. An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost". Streaming Expressions are exposed via the "/streaming" handler, with "
http://www.openwall.com/lists/oss-security/2024/02/09/2http://www.openwall.com/lists/oss-security/2024/02/09/3https://solr.apache.org/security.html#cve-2023-50298-apache-solr-can-expose-zookeeper-credentials-via-streaming-expressionshttp://www.openwall.com/lists/oss-security/2024/02/09/2http://www.openwall.com/lists/oss-security/2024/02/09/3https://solr.apache.org/security.html#cve-2023-50298-apache-solr-can-expose-zookeeper-credentials-via-streaming-expressions
2024-02-09
Published