Lucene search

K
cvelistApacheCVELIST:CVE-2021-29262
HistoryApr 13, 2021 - 6:35 a.m.

CVE-2021-29262 Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings

2021-04-1306:35:21
CWE-522
apache
www.cve.org
1

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.4%

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.

CNA Affected

[
  {
    "product": "Apache Solr",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "8.8.2",
        "status": "affected",
        "version": "Apache Solr",
        "versionType": "custom"
      }
    ]
  }
]

References

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.4%