S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 9, 2024

CVE-2023-50290 Scanner

Detects 'Information Disclosure' vulnerability in Apache Solr affects v. from 9.0.0 before 9.3.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-50290
6.5
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variables to hide, however, the default list is designed to work for known secret Java system properties. Environment variables cannot be strictly defined in Solr, like Java system properties can be, and may be set for the entire host, unlike Java system properties which are set per-Java-proccess. The Solr Metrics API is protected by the "metrics-read" permission. Therefore, Solr Clouds with Authorization setup will only be vulnerable via users with the "metrics-read" permission. This issue affects Apache Solr: from 9.0.0 before 9.3.0. Users are recommended to upgrade to version 9.3.0 or later, in which environment variables are not published via the Metrics API.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache Solrby Apache Software Foundation
AFFECTED< 9.3.0SAFE ✓≥ 9.3.0
Updated Aug 22, 2026View on NVD →
Detail

Securing Apache Solr Against CVE-2023-50290: Insights and Actions

Addressing Information Disclosure in Apache Solr: CVE-2023-50290

Introduction to Apache Solr

Apache Solr is an open-source search platform part of the Apache Lucene project. It is widely used for enterprise search and analytics purposes across various types of data sources. Solr provides full-text search, hit highlighting, faceted search, real-time indexing, dynamic clustering, and database integration, making it a powerful tool for data retrieval and management.

About the CVE-2023-50290 Vulnerability

CVE-2023-50290 is an Information Disclosure vulnerability found in Apache Solr versions from 9.0.0 to before 9.3.0. It involves the Metrics API inadvertently exposing unprotected environment variables to unauthorized actors. This exposure occurs because Solr's Metrics API can publish all environment variables available to the Solr instance, where the default configuration may not adequately protect sensitive information.

Potential Impact of CVE-2023-50290 Exploitation

Exploiting CVE-2023-50290 could allow attackers to gain unauthorized access to sensitive information, such as environment variables that may contain critical configuration details or credentials. This vulnerability poses a significant risk, as it could lead to further exploitation of the system, data breaches, and compromise of the Solr environment's security and integrity.

Why S4E is Essential

For those not yet leveraging S4E, this situation underscores the importance of continuous threat exposure management. The platform’s dedicated CVE-2023-50290 scanner helps organizations proactively detect and address vulnerabilities, reinforcing defenses against information disclosure and enhancing overall cybersecurity resilience.

 

References

Solution Advice

To mitigate this vulnerability, it is recommended to:

  • Upgrade Solr: Move to Apache Solr version 9.3.0 or later, where the issue has been resolved.
  • Configure environment variables: Adjust settings to ensure sensitive information is not exposed through the Metrics API.
  • Implement access controls: Strengthen Solr Cloud's authorization to restrict access to the Metrics API.
  • Regularly audit: Conduct periodic security reviews and audits of your Solr environment to identify and rectify potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.