CVE-2023-50290 is a medium-severity vulnerability in Apache Solr versions 9.0.0 through 9.2.x, allowing the Solr Metrics API to expose sensitive environment variables to unauthorized actors. An attacker with "metrics-read" permission can access these variables, potentially leading to information disclosure. While not actively exploited in the wild, public Nuclei templates exist, and its high EPSS and FAUCET scores indicate a significant risk. Organizations using affected Solr versions should upgrade to 9.3.0 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.3.0CPE match | cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.