Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection

Overview :
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

CVE-2018-11802

 

Subject: CVE-2018-11802: Apache Solr authorization bug vulnerability disclosure

CVE-2018-11802: Apache Solr authorization bug disclosure
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected: Apache Solr 7.6 or less

Description:
jira  ticket : https://issues.apache.org/jira/browse/SOLR-12514
In apache Solr the cluster can be partitioned into multiple
collections and only a subset of nodes actually host any given
collection. However, if a node receives a request for a collection it
does not host, it proxies the request to a relevant node and serves
the request. Solr bypasses all authorization settings for such
requests. This affects all Solr versions that uses the default
authorization mechanism of Solr (RuleBasedAuthorizationPlugin)

Mitigation:
A fix is provided in Solr 7.7 version and upwards. If you use Solr's
authorization mechanism, please upgrade to a version newer than Solr
7.7.

 

Common Vulnerabilityies and Exposures

Google Chrome prior 95.0.4638.54 WebApp Installer Remote Code Execution

A vulnerability has been found in Google Chrome (Web Browser) and classified as critical. Affected by this vulnerability is an unknown functionality of the component WebApp Installer. Upgrading to version 95.0.4638.54 eliminates this vulnerability.

Cisco IOS XE SD-WAN CLI os command injection [CVE-2021-1529]

A vulnerability, which was classified as critical, was found in Cisco IOS XE SD-WAN (Router Operating System) (the affected version unknown). This affects an unknown functionality of the component CLI. Upgrading eliminates this vulnerability.

Cisco Integrated Management Controller Web-based Management Interface denial of service

A vulnerability has been found in Cisco Integrated Management Controller (the affected version is unknown) and classified as problematic. This vulnerability affects some unknown functionality of the component Web-based Management Interface. Upgrading eliminates this vulnerability.