CVE-2018-11802

unknown
Published 2022-02-09 · Modified 2025-11-10
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2
VIR risk

Description

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-11802

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.solr:solr-parent>=7.0.0,<7.7.07.7.0
java Mavenorg.apache.solr:solr-parent<6.6.66.6.6
java Mavenorg.apache.solr:solr-core>=7.0.0,<7.7.07.7.0
java Mavenorg.apache.solr:solr-core<6.6.66.6.6

References

Verify integrity in audit chain (admin only). AS-IS.