VDB

BIT-solr-2020-9492

BIT-solr-2020-9492 PUBLISHED CVSS 8.800000190734863 HIGH

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0 to 3.1.3, and 2.0.0 to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Bitnamisolr8.6.0, 8.6.2, 8.6.0

Exploit Intelligence

Timeline

  • Mar 6, 2024 CVE Published
  • Mar 20, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›