UBUNTU-CVE-2021-29262
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-29262
Summary:
Details: When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.
References: https://ubuntu.com/security/CVE-2021-29262, https://lists.apache.org/thread.html/r536da4c4e4e406f7843461cc754a3d0a3fe575aa576e2b71a9cd57d0%40%3Cannounce.apache.org%3E, https://www.cve.org/CVERecord?id=CVE-2021-29262
Affected packages
Package
Name: lucene-solr
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.1~esm4?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
