Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-15453

Harmless Security Error Could Cause Issues for some Users

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 9.0, 8.8.2
    • 9.0
    • Admin UI, security
    • None

    Description

      There is an error globally around certain images being blocked due to violating the Content Security Policies. To address this, there needs to be a change in the jetty.xml to add the data: directive to img-src. The complete entry should look like this: img-src 'self' data:

      The main issue is that this error could lead to more challenges for some users of Solr if observed by their internal security teams even though it's not much of an issue. I could not identify which specific images were blocked.

      To reproduce, you can build master and visit the Admin UI and check the browser console.

      Attachments

        1. main_branch.png
          543 kB
          Marcus Eagan
        2. example_security_policy.png
          437 kB
          Marcus Eagan

        Issue Links

          Activity

            People

              houston Houston Putman
              marcussorealheis Marcus Eagan
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 10m
                  10m