🛡️ GHSA-7crc-r3wg-cfgf — ezplatform-solr-search-engine
Description
Json response for search reveals Solr credentials
Impact
An error in Ibexa's Solr search engine results in potential exposure of Solr credentials. This is a critical vulnerability and all supported versions of the engine are affected. Those not using the Solr search engine are not affected.
Patches
The issue is fixed in all supported versions of ezsystems/ezplatform-solr-search-engine, see "Patched versions".
An advisory is also published for ibexa/solr, please see that repository.
Commit: https://github.com/ezsystems/ezplatform-solr-search-engine/commit/1005e02cc32ff15a705857fa56171528a83b9c3e
Workarounds
None.
References
https://developers.ibexa.co/security-advisories/ibexa-sa-2023-005-vulnerabilities-in-solr-search-and-file-downloads
Weakness class
GHSA-7crc-r3wg-cfgf is classified as CWE-200: Exposure of Sensitive Information. Information that should stay internal is disclosed to someone who is not authorised to see it.
Affected software
GHSA-7crc-r3wg-cfgf is recorded against 1 package.
- ezsystems/ezplatform-solr-search-engine (from 1.7.0 up to 1.7.12)
Timeline and source
Published on 3 November 2023 and last revised on 4 December 2024. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| ezsystems/ezplatform-solr-search-engine | 1.7.0 | 1.7.12 |
References
Exploit Protection
Are you running ezplatform-solr-search-engine?
GHSA-7crc-r3wg-cfgf carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For GHSA-7crc-r3wg-cfgf →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.