Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-15453

Harmless Security Error Could Cause Issues for some Users

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 9.0, 8.8.2
    • 9.0
    • Admin UI, security
    • None

    Description

      There is an error globally around certain images being blocked due to violating the Content Security Policies. To address this, there needs to be a change in the jetty.xml to add the data: directive to img-src. The complete entry should look like this: img-src 'self' data:

      The main issue is that this error could lead to more challenges for some users of Solr if observed by their internal security teams even though it's not much of an issue. I could not identify which specific images were blocked.

      To reproduce, you can build master and visit the Admin UI and check the browser console.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            houston Houston Putman
            marcussorealheis Marcus Eagan
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 10m
                10m

                Slack

                  Issue deployment