SCA: security update for org.apache.solr:solr-core (GHSA-4wxw-42wx-2wfx)

high Tenable Self-Hosted Container Security Plugin ID 410463

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code
Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from
9.0.0 before 9.3.0. The Schema Designer was introduced to allow users to more easily configure and test
new Schemas and configSets. However, when the feature was created, the "trust" (authentication) of these
configSets was not considered. External library loading is only available to configSets that are "trusted"
(created by authenticated users), thus non-authenticated users are unable to perform Remote Code
Execution. Since the Schema Designer loaded configSets without taking their "trust" into account,
configSets that were created by unauthenticated users were allowed to load external libraries when used in
the Schema Designer. Users are recommended to upgrade to version 9.3.0, which fixes the issue.
(CVE-2023-50292)

See Also

https://github.com/advisories/GHSA-4wxw-42wx-2wfx

Plugin Details

Severity: High

ID: 410463

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.71

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-50292

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/9/2024

Vulnerability Publication Date: 2/9/2024

Reference Information

CVE: CVE-2023-50292

cwe: CWE-732