Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Done
-
None
-
None
Description
A lot of security questions arise from various options to add custom libraries via a solrconfig.xml. When using the recommended solr auth plugin, a user requires the config-edit permission to edit this file. And custom libraries will only be used when the solrconfig is trusted by Solr.
Right now the config-edit permission documentation does not explicitly spell out that the permission gives users the ability to install any custom library to Solr. We should fix this to reduce confusion around RCEs.
With our antora docs, I suggest we backport this documentation change to 9.0 and 9.1, and also update 8.11 for the next patch release.
Attachments
Issue Links
- links to