First published: Tue Apr 13 2021(Updated: )
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Solr | <8.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29943 is a vulnerability in Apache Solr versions prior to 8.8.2 that allows incorrect authorization resolution on receiving hosts when using ConfigurableInternodeAuthHadoopPlugin for authentication.
CVE-2021-29943 affects Apache Solr versions prior to 8.8.2 when using ConfigurableInternodeAuthHadoopPlugin for authentication.
CVE-2021-29943 has a severity rating of 9.1 (critical).
To fix CVE-2021-29943, you should upgrade Apache Solr to version 8.8.2 or newer.
Yes, you can find more information about CVE-2021-29943 at the following references: [Reference 1](https://lists.apache.org/thread.html/r91dd0ff556e0c9aab4c92852e0e540c59d4633718ce12881558cf44d%40%3Cusers.solr.apache.org%3E), [Reference 2](https://security.netapp.com/advisory/ntap-20210604-0009/).