← voltar
CVE-2024-45216criticalexploração observadaCWE-287CWE-863

Apache Solr: Authentication bypass possible using a fake URL Path ending

100Vexday Risk Score

Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.

ssvc Actcvss 9.8epss 91%
da publicação à arma47 dias
Publicada no NVD16 de out.
1ª PoC+47d
VulnCheck+380d
probabilidade de exploração
91%top 1% das CVEs
exploração observada
simVulnCheck
3 exploit(s) público(s)
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.