← back
CVE-2021-29943CWE-863

Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 5.4%
exploitation probability
5.4%top 8% of all CVEs
observed exploitation
nono source reports it
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.