#VU52061 Improper Authorization in Apache Solr - CVE-2021-29943
Published: April 13, 2021
Apache Solr
Apache Foundation
Description
The vulnerability allows a remote user to gain access to otherwise restricted functionality.
The vulnerability exists in ConfigurableInternodeAuthHadoopPlugin implementation. Apache Solr forwards distributed requests using server credentials instead of original client credentials. A remote user can abuse such behavior to gain access to otherwise restricted functionality.