Information disclosure in Apache Solr - CVE-2023-50298
Published: February 20, 2024
Vulnerability identifier: #VU86631
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50298
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to ZooKeeper credentials via Streaming Expressions
Affected software
Apache Solr
Log Analysis
watsonx.data
IBM OpenPages with Watson
Operational Decision Manager
Log Analysis
watsonx.data
IBM OpenPages with Watson
Operational Decision Manager
How to mitigate CVE-2023-50298
Install updates from vendor's website.
Apache Solr - addressed in versions 8.11.3, 9.4.1
Log Analysis - update to 1.3.8.2
watsonx.data - update to 2.1
IBM OpenPages with Watson - addressed in versions 8.3.0.3, 9.0.0.3
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 54, 8.11.0.1 Interim fix 29, 8.11.1 Interim fix 21, 8.12.0.1 Interim fix 3
Log Analysis - update to 1.3.8.2
watsonx.data - update to 2.1
IBM OpenPages with Watson - addressed in versions 8.3.0.3, 9.0.0.3
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 54, 8.11.0.1 Interim fix 29, 8.11.1 Interim fix 21, 8.12.0.1 Interim fix 3
External References
- https://solr.apache.org/security.html#cve-2023-50298-apache-solr-can-expose-zookeeper-credentials-via-streaming-expressions
- http://www.openwall.com/lists/oss-security/2024/02/09/3
- http://www.openwall.com/lists/oss-security/2024/02/09/2
- https://lists.apache.org/thread/lz0obpo1y4xh8xgnw2sylkpcqbs670vy