Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2021-29943
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior…
Technology
Apache Solr
CVSS Score
9.1 / 10.0
Affected Versions
<8.8.2
Upstream Fix
See upstream advisory
Published
April 13, 2021
OSSeva Coverage
Fixed upstream
Description
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.
Is your Apache Solr deployment affected?
If you're running <8.8.2, you need this patch. Book a discovery call to get covered.