CVE-2021-29943
CRITICALApache Solr < 8.8.2 - Incorrect Authorization via ConfigurableInternodeAuthHadoopPlugin
Title source: llmDescription
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts.
References (2)
Core 2
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread.html/r91dd0ff556e0c9aab4c92852e0e540c59d4633718ce12881558cf44d%40%3Cusers.solr.apache.org%3E
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210604-0009/
Scores
CVSS v3
9.1
EPSS
0.0580
EPSS Percentile
90.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-863
Status
published
Products (2)
apache/solr
< 8.8.2
org.apache.solr/solr-parent
0 - 8.8.2Maven
Published
Apr 13, 2021
Tracked Since
Feb 18, 2026