SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Apache Solr PKIAuthenticationPlugin Authentication Bypass

Category: WEB-ATTACKS      

Apache solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path.


Relevant Information