CVE-2021-29262

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.39 % (74th)
0.39% Progress
Affected Products 1
Advisories 1

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.

Weaknesses
CWE-522
Insufficiently Protected Credentials
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2021-04-13 07:15:12
(3 years ago)
Updated Date
2023-11-07 03:32:34
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Solr prior 8.8.2 version cpe:2.3:a:apache:solr < 8.8.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...