{"id":"GHSA-7crc-r3wg-cfgf","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7crc-r3wg-cfgf","summary":"Json response for search reveals Solr credentials","details":"### Impact\nAn error in Ibexa's Solr search engine results in potential exposure of Solr credentials. This is a critical vulnerability and all supported versions of the engine are affected. Those not using the Solr search engine are not affected.\n\n### Patches\nThe issue is fixed in all supported versions of ezsystems/ezplatform-solr-search-engine, see \"Patched versions\".\nAn advisory is also published for ibexa/solr, please see that repository.\nCommit: https://github.com/ezsystems/ezplatform-solr-search-engine/commit/1005e02cc32ff15a705857fa56171528a83b9c3e\n\n### Workarounds\nNone.\n\n### References\nhttps://developers.ibexa.co/security-advisories/ibexa-sa-2023-005-vulnerabilities-in-solr-search-and-file-downloads\n","published":"2023-11-03T19:50:18Z","modified":"2024-12-04T05:35:48.575710Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ezsystems/ezplatform-solr-search-engine","fixedVersion":"3.3.15"},{"ecosystem":"Packagist","name":"ezsystems/ezplatform-solr-search-engine","fixedVersion":"2.0.2"},{"ecosystem":"Packagist","name":"ezsystems/ezplatform-solr-search-engine","fixedVersion":"1.7.12"}],"fix":{"url":"https://github.com/ezsystems/ezplatform-solr-search-engine/commit/c382037208f38f18efb5a6b21d6936efc55fc408","label":"ezsystems/ezplatform-solr-search-engine@c382037"},"references":[{"type":"WEB","url":"https://github.com/ezsystems/ezplatform-solr-search-engine/security/advisories/GHSA-7crc-r3wg-cfgf"},{"type":"WEB","url":"https://github.com/ezsystems/ezplatform-solr-search-engine/commit/c382037208f38f18efb5a6b21d6936efc55fc408"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezplatform-solr-search-engine"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:35:48.575710Z"}}