Details
-
Bug
-
Status: Closed
-
Blocker
-
Resolution: Fixed
-
8.11.2
-
None
Description
Before an 8.11.3 release, https://issues.apache.org/jira/browse/SOLR-16480 needs to be backported, thus creating this as a blocker.
Here I am assuming that 8.x is vulnerable to the same attack, which should be investigated.
Attachments
Attachments
Issue Links
- relates to
-
SOLR-17104 Protect lib directories from being writable
- Open
- supercedes
-
SOLR-16480 RCE via Backup/Restore APIs that allow for deployment of executables in malicious ConfigSets
- Closed