{"id":"GHSA-v6xp-ccvx-w52m","summary":"Json response for search reveals Solr credentials","details":"### Impact\nAn error in Ibexa's Solr search engine results in potential exposure of Solr credentials. This is a critical vulnerability and all supported versions of the engine are affected. Those not using the Solr search engine are not affected.\n\n### Patches\nThe issue is fixed in all supported versions of ibexa/solr, see \"Patched versions\".\nAn advisory is also published for ezsystems/ezplatform-solr-search-engine, please see that repository.\nCommit: https://github.com/ibexa/solr/commit/2f8b711874bee1ebe31fb8a6362e0c8e52c53012\n\n### Workarounds\nNone.\n\n### References\nhttps://developers.ibexa.co/security-advisories/ibexa-sa-2023-005-vulnerabilities-in-solr-search-and-file-downloads\n","modified":"2024-12-04T05:28:33.215367Z","published":"2023-11-03T19:48:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-11-03T19:48:16Z","nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/ibexa/solr/security/advisories/GHSA-v6xp-ccvx-w52m"},{"type":"WEB","url":"https://github.com/ibexa/solr/commit/2f8b711874bee1ebe31fb8a6362e0c8e52c53012"},{"type":"PACKAGE","url":"https://github.com/ibexa/solr"}],"affected":[{"package":{"name":"ibexa/solr","ecosystem":"Packagist","purl":"pkg:composer/ibexa/solr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.5.0"},{"fixed":"4.5.4"}]}],"versions":["v4.5.0","v4.5.1","v4.5.2","v4.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-v6xp-ccvx-w52m/GHSA-v6xp-ccvx-w52m.json"}}],"schema_version":"1.9.0"}