New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata.
ConfigSets that do not contain the flag are trusted implicitly if the metadata is missing, therefore this leads to "trusted" ConfigSets that may not have been created with an Authenticated request.
"trusted" ConfigSets are able to load custom code into classloaders, therefore the flag is supposed to only be set when the request that uploads the ConfigSet is Authenticated & Authorized.
This issue affects Apache Solr: from 6.6.0 before 8.11.4, from 9.0.0 before 9.7.0. This issue does not affect Solr instances that are secured via Authentication/Authorization.
Users are primarily recommended to use Authentication and Authorization when running Solr. However, upgrading to version 9.7.0, or 8.11.4 will mitigate this issue otherwise.
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  Github GHSA | GHSA-h7w9-c5vx-x7j3 | Insecure Default Initialization of Resource vulnerability in Apache Solr | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Tue, 01 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Apache Apache solr | |
| CPEs | cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* | |
| Vendors & Products | Apache Apache solr | 
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Wed, 16 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Apache Software Foundation Apache Software Foundation apache Solr | |
| CPEs | cpe:2.3:a:apache_software_foundation:apache_solr:*:*:*:*:*:*:*:* | |
| Vendors & Products | Apache Software Foundation Apache Software Foundation apache Solr | |
| Metrics | cvssV3_1 
 
 | 
Wed, 16 Oct 2024 08:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that do not contain the flag are trusted implicitly if the metadata is missing, therefore this leads to "trusted" ConfigSets that may not have been created with an Authenticated request. "trusted" ConfigSets are able to load custom code into classloaders, therefore the flag is supposed to only be set when the request that uploads the ConfigSet is Authenticated & Authorized. This issue affects Apache Solr: from 6.6.0 before 8.11.4, from 9.0.0 before 9.7.0. This issue does not affect Solr instances that are secured via Authentication/Authorization. Users are primarily recommended to use Authentication and Authorization when running Solr. However, upgrading to version 9.7.0, or 8.11.4 will mitigate this issue otherwise. | |
| Title | Apache Solr: ConfigSets created during a backup restore command are trusted implicitly | |
| Weaknesses | CWE-1188 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-10-16T15:08:26.625Z
Reserved: 2024-08-23T17:50:50.872Z
Link: CVE-2024-45217
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-10-16T08:03:37.258Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-10-16T08:15:05.353
Modified: 2025-07-01T20:28:31.793
Link: CVE-2024-45217
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.