{"id":"GHSA-v6xp-ccvx-w52m","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v6xp-ccvx-w52m","summary":"Json response for search reveals Solr credentials","details":"### Impact\nAn error in Ibexa's Solr search engine results in potential exposure of Solr credentials. This is a critical vulnerability and all supported versions of the engine are affected. Those not using the Solr search engine are not affected.\n\n### Patches\nThe issue is fixed in all supported versions of ibexa/solr, see \"Patched versions\".\nAn advisory is also published for ezsystems/ezplatform-solr-search-engine, please see that repository.\nCommit: https://github.com/ibexa/solr/commit/2f8b711874bee1ebe31fb8a6362e0c8e52c53012\n\n### Workarounds\nNone.\n\n### References\nhttps://developers.ibexa.co/security-advisories/ibexa-sa-2023-005-vulnerabilities-in-solr-search-and-file-downloads\n","published":"2023-11-03T19:48:16Z","modified":"2024-12-04T05:28:33.215367Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ibexa/solr","fixedVersion":"4.5.4"}],"fix":{"url":"https://github.com/ibexa/solr/commit/2f8b711874bee1ebe31fb8a6362e0c8e52c53012","label":"ibexa/solr@2f8b711"},"references":[{"type":"WEB","url":"https://github.com/ibexa/solr/security/advisories/GHSA-v6xp-ccvx-w52m"},{"type":"WEB","url":"https://github.com/ibexa/solr/commit/2f8b711874bee1ebe31fb8a6362e0c8e52c53012"},{"type":"PACKAGE","url":"https://github.com/ibexa/solr"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:28:33.215367Z"}}