Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-13463

Solr admin user credentials defined with -Dbasicauth property during start is visible in admin UI to any user.

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Workaround
    • 7.7.1
    • None
    • Admin UI
    • QA

    Description

      We have configured Solr basic authentication in our environment and used Dbasicauth property to define username:password. Since these property will be added to Solr startup, the Solr admin username & password details defined with -Dbasicauth property are displayed in plain text format to all users who are able to login into admin UI interface in JVM & Java properties sections. So even a read user who has privileges to login admin UI can able to see admin user username & password details.

      Attachments

        Activity

          People

            Unassigned Unassigned
            vkommu Vinodh
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: