Apache Solr Product Security Update Advisory (CVE-2023-50386)

Overview

 

An update has been made available to address a vulnerability in the Apache Solr product. users of affected versions are advised to update to the latest version.

 

Affected Products

 

Apache Solr

  • 6.0.0 to 8.11.2 or below
  • 9.x.x version prior to 9.4.1

 

Resolved Vulnerabilities

 

Backup/Restore APIs allow for deployment of executables in malicious ConfigSets (CVE-2023-50386)

 

Vulnerability Patches

 

vulnerability patches were made available in the February 8, 2024 update. Please update to the latest Vulnerability Patches version according to the Referenced Sites.

Apache Solr version 8.11.3, 9.4.1

 

Referenced Sites

 

[1] CVE-2023-50386 Detail
https://nvd.nist.gov/vuln/detail/CVE-2023-50386
[2] Solr™ Security News
https://solr.apache.org/security.html#cve-2023-50386-apache-solr-backuprestore-apis-allow-for-deployment-of-executables-in-malicious-configsets