Apache Solr gater than 8.8.1 Arbitrary File Read

Published on 01 Oct 2021
Vulnerability

Apache Solr is an open-source enterprise search platform from the Apache Lucene project. There is a file read vulnerability in Apache Solr, and an attacker can access sensitive information from the target server in unauthorised circumstances. Prior to version 8.8.2, distributed requests were forwarded/proxied using server credentials instead of the original client credentials.

Mitigation / Precaution

If you are using Solr <= 8.8.1, Upgrade to Solr 8.8.2 or greater. Use another authentication plugin, such as KerberosPlugin or HadoopAuthPlugin.

Rejah Rehim
Written by
Co-founder, Director

Rejah brings more than 12 years of industry experience in Information Technology. He is a fervent security enthusiast and serves as a Project Leader at OWASP Foundation, and Commander (Hon.) at Kerala Police. He has authored two books titled “Effective Python Penetration Testing” and “Python Penetration Testing Cookbook” and is the creator of 9 Mozilla add-ons.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo