QID 731149
Date Published: 2024-02-19
QID 731149: Apache Solr Multiple Vulnerabilites (CVE-2023-50386,CVE-2023-50298)
Solr is highly reliable, scalable and fault tolerant, providing distributed indexing, replication and load-balanced querying, automated failover and recovery, centralized configuration and more. Solr powers the search and navigation features of many of the world's largest internet sites
CVE-2023-50298 : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.
CVE-2023-50386: Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.
Affected Versions:
Solr 6.0.0 to 8.11.2
Solr 9.0.0 before 9.4.1
QID Detection Logic:
This QID sends a HTTP GET request to "solr/admin/info/system" endpoint and check for Apache Solr Version.
Note: This issue has Mitigation, hence the detection is kept as potential.
Successful exploitation of this vulnerability affects Exposure of Sensitive Information and Improper Control of Dynamically-Managed Code Resources.
CVEs related to QID 731149
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Solr advisory |
|