QID 731080
Date Published: 2024-01-18
QID 731080: Apache Solr Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Solr is highly reliable, scalable and fault tolerant, providing distributed indexing, replication and load-balanced querying, automated failover and recovery, centralized configuration and more. Solr powers the search and navigation features of many of the world's largest internet sites
CVE-2023-50290 : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance.
Affected Versions:
Solr 9.0 to 9.2.1
QID Detection Logic:
This QID sends a HTTP GET request to "solr/admin/info/system" endpoint and check for Apache Solr Version.
Note: This issue has Mitigation, hence the detection is kept as potential.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.
CVEs related to QID 731080
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Solr advisory |
|