Bug 1869167 (CVE-2020-13941) - CVE-2020-13941 solr: replication handler allows a read-write operations to any location the solr user can access
Summary: CVE-2020-13941 solr: replication handler allows a read-write operations to an...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2020-13941
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1869168
Blocks: 1869172
TreeView+ depends on / blocked
 
Reported: 2020-08-17 07:07 UTC by Marian Rehak
Modified: 2021-02-16 19:29 UTC (History)
52 users (show)

Fixed In Version: Solr 8.6.0
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Solr. The Replication handler allows commands backup, restore, and delete backup that take non-validated allocation parameters which may result in the exfiltration of sensitive data such as OS user hashes (NTLM/LMhashes). The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Clone Of:
Environment:
Last Closed: 2020-08-18 21:15:35 UTC
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2020-08-17 07:07:42 UTC
In Solr version 8.6.0, the Replication handler allows commands backup, restore and deleteBackup that takeunvalidated alocation parameter, i.e you could read/write to any location the solr user can access. Launching SMB attacks which may result in the exfiltration of sensitive data such as OS user hashes (NTLM/LMhashes). In case of misconfigured systems, SMB Relay Attacks which can lead to user impersonation on SMB Shares or, in a worse-case scenario, Remote Code Execution.

Reference:

https://www.openwall.com/lists/oss-security/2020/08/15/1

Comment 1 Marian Rehak 2020-08-17 07:08:13 UTC
Created solr3 tracking bugs for this issue:

Affects: fedora-31 [bug 1869168]

Comment 9 Product Security DevOps Team 2020-08-18 21:15:35 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-13941

Comment 10 Eric Christensen 2020-08-24 15:41:22 UTC
Statement:

Red Hat JBoss Fuse 6, Red Hat Fuse 7, and Red Hat Integration Camel K using camel-solr are not directly affected by this vulnerability as the camel-solr component uses the client library solr-j and the vulnerability lies in the solr server itself. We advise customers using solr to investigate the usage of the server and ensure it is safe.


Note You need to log in before you can comment on or make changes to this bug.