VYPR
Unrated severityNVD Advisory· Published Nov 7, 2023· Updated Sep 4, 2024

Apache OFBiz: Execution of Solr plugin queries without authentication

CVE-2023-46819

Description

Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.

Users are recommended to upgrade to version 18.12.09

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authentication in Apache OFBiz Solr plugin allows unauthenticated attackers to execute arbitrary queries against Solr, enabling data exposure.

Vulnerability

A missing authentication flaw exists in the Apache OFBiz Solr plugin in versions before 18.12.09. The Solr plugin did not require authentication, allowing any unauthenticated user to access and interact with the Solr search engine interface exposed by OFBiz. This issue affects all OFBiz releases prior to the fixed version [1][2][3].

Exploitation

An attacker with network access to the OFBiz instance can send requests directly to the Solr plugin without needing any authentication, session, or prior access. By crafting HTTP requests to Solr endpoints, the attacker can execute arbitrary search queries against the Solr core used by OFBiz, bypassing any intended access controls [1][3].

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary queries against the Solr search index, leading to unauthorized disclosure of sensitive data stored in the Solr index. Depending on the data indexed, this could include customer information, order details, or other business data. The attacker does not gain OS-level access but can read any data indexed by Solr [1][3].

Mitigation

The vulnerability is fixed in Apache OFBiz version 18.12.09, released in November 2023 [2][3]. All users are recommended to upgrade to 18.12.09 or later. No workaround is documented, but restricting network access to the OFBiz Solr plugin via firewall rules may reduce exposure until an upgrade can be applied [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Apache/Apache OFBizllm-create2 versions
    <18.12.09+ 1 more
    • (no CPE)range: <18.12.09
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.