GHSA-7crc-r3wg-cfgf

    Dashboard / Vulnerabilities / GHSA-7crc-r3wg-cfgf

    GHSA-7crc-r3wg-cfgf

    Published: 3 Nov 2023Last Modified: 4 Dec 2024

    Summary: Json response for search reveals Solr credentials

    Details: ### Impact An error in Ibexa's Solr search engine results in potential exposure of Solr credentials. This is a critical vulnerability and all supported versions of the engine are affected. Those not using the Solr search engine are not affected. ### Patches The issue is fixed in all supported versions of ezsystems/ezplatform-solr-search-engine, see "Patched versions". An advisory is also published for ibexa/solr, please see that repository. Commit: https://github.com/ezsystems/ezplatform-solr-search-engine/commit/1005e02cc32ff15a705857fa56171528a83b9c3e ### Workarounds None. ### References https://developers.ibexa.co/security-advisories/ibexa-sa-2023-005-vulnerabilities-in-solr-search-and-file-downloads

    Affected packages

    Package

    Name: ezsystems/ezplatform-solr-search-engine

    Purl: pkg:composer/ezsystems/ezplatform-solr-search-engine

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.3.0
    Fixed -3.3.15

    Affected versions

    v3.3.0
    v3.3.1
    v3.3.10
    v3.3.11
    v3.3.12
    v3.3.13
    v3.3.14
    v3.3.2
    v3.3.3
    v3.3.4
    v3.3.5
    v3.3.6
    v3.3.7
    v3.3.8
    v3.3.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7crc-r3wg-cfgf | CVE-DB