Description
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1201 | When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts. |
Github GHSA |
GHSA-vf7p-j8x6-xvwp | Incorrect Authorization in Apache Solr |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T22:18:03.277Z
Reserved: 2021-04-01T00:00:00.000Z
Link: CVE-2021-29943
No data.
Status : Modified
Published: 2021-04-13T07:15:12.403
Modified: 2024-11-21T06:02:01.777
Link: CVE-2021-29943
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA