QID 981601
QID 981601: Java (maven) Security Update for org.apache.solr:solr-core (GHSA-2289-pqfq-6wx7)
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2289-pqfq-6wx7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2289-pqfq-6wx7 -
github.com/advisories/GHSA-2289-pqfq-6wx7
CVEs related to QID 981601
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2289-pqfq-6wx7 | org.apache.solr:solr-core |
|