Vulnerability Description
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Solr | < 8.8.2 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r1171f6417eeb6d5e1206d53e2b2ff2d6ee14026f8b
- https://lists.apache.org/thread.html/r1e92a2eff6c47a65c4a6e95e809a9707181de76f80
- https://lists.apache.org/thread.html/r51b29ff62060b67bc9999ded5e252b36b09311fe5a
- https://lists.apache.org/thread.html/r536da4c4e4e406f7843461cc754a3d0a3fe575aa57Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r7151081abab92a827a607205c4260b0a3d22280b52
- https://lists.apache.org/thread.html/r8d35eeb9a470d2682b5bcf3be0b8942faa7e28f9ca
- https://lists.apache.org/thread.html/r9c4ce6903218c92ef2583070e64af5a69e483821c4
- https://lists.apache.org/thread.html/rb6db683903174eaa44ec80cc118a38574319b0d418
- https://lists.apache.org/thread.html/rbc680cbfd745f22d182158217428a296e8e398cde1
- https://lists.apache.org/thread.html/rd85f87e559ee27e9c69795e3ad93a77621895e0328
- https://lists.apache.org/thread.html/ref84e60192f4bdc3206b247f260513e8d4e71f3e20
- https://security.netapp.com/advisory/ntap-20210604-0009/Third Party Advisory
- https://lists.apache.org/thread.html/r1171f6417eeb6d5e1206d53e2b2ff2d6ee14026f8b
- https://lists.apache.org/thread.html/r1e92a2eff6c47a65c4a6e95e809a9707181de76f80
- https://lists.apache.org/thread.html/r51b29ff62060b67bc9999ded5e252b36b09311fe5a
FAQ
What is CVE-2021-29262?
CVE-2021-29262 is a vulnerability with a CVSS score of 7.5 (HIGH). When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only use...
How severe is CVE-2021-29262?
CVE-2021-29262 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29262?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Solr.