SCA: security update for org.apache.solr:solr-core (GHSA-3hwc-rqwp-v36q)

high Tenable Self-Hosted Container Security Plugin ID 409557

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from
6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process'
Java system properties, /admin/info/properties, was only setup to hide system properties that had
"password" contained in the name. There are a number of sensitive system properties, such as "basicauth"
and "aws.secretKey" do not contain "password", thus their values were published via the
"/admin/info/properties" endpoint. This endpoint populates the list of System Properties on the home
screen of the Solr Admin page, making the exposed credentials visible in the UI. This
/admin/info/properties endpoint is protected under the "config-read" permission. Therefore, Solr Clouds
with Authorization enabled will only be vulnerable through logged-in users that have the "config-read"
permission. Users are recommended to upgrade to version 9.3.0 or 8.11.3, which fixes the issue. A single
option now controls hiding Java system property for all endpoints, "-Dsolr.hiddenSysProps". By default all
known sensitive properties are hidden (including "-Dbasicauth"), as well as any property with a name
containing "secret" or "password". Users who cannot upgrade can also use the following Java system
property to fix the issue: '-Dsolr.redaction.system.pattern=.*(password|secret|basicauth).*'
(CVE-2023-50291)

See Also

https://github.com/advisories/GHSA-3hwc-rqwp-v36q

Plugin Details

Severity: High

ID: 409557

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.69

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-50291

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/9/2024

Vulnerability Publication Date: 2/9/2024

Reference Information

CVE: CVE-2023-50291

cwe: CWE-522