CVE-2015-5506: Infoleak
Published Aug 18, 2015
·Updated
The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content via a search.
Affected Software
2 affected components
Apache Solr Real-time Project Apache Solr Real-time Drupal=7.x-1.0
Apache Solr Real-time Project Apache Solr Real-time Drupal=7.x-1.1
Remediation
Patch Available
Patch Available
Event History
Aug 18, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5506?
CVE-2015-5506 is considered a high severity vulnerability due to its potential to expose unpublished content.
2
How do I fix CVE-2015-5506?
To fix CVE-2015-5506, upgrade the Apache Solr Real-Time module to version 7.x-1.2 or later.
3
What type of attacks are possible with CVE-2015-5506?
CVE-2015-5506 allows remote attackers to retrieve unpublished content through an unauthenticated search.
4
Which versions are affected by CVE-2015-5506?
CVE-2015-5506 affects Apache Solr Real-Time module versions 7.x-1.0 and 7.x-1.1.
5
Is there a known exploit for CVE-2015-5506?
Yes, CVE-2015-5506 is known to be exploitable, allowing attackers to expose sensitive information.