CVE-2017-7660 is a high-severity vulnerability affecting Apache Solr, specifically when PKI-based inter-node communication is enabled and certain authentication plugins are used. An attacker can craft a malicious node name to trick legitimate cluster members into accepting an unauthorized node, potentially leading to unauthorized data modification (integrity impact). The attack is network-based and low complexity, but there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.3.0CPE matchmatch criteria | cpe:2.3:a:apache:solr:5.3.0:*:*:*:*:*:*:* | ||
5.3.1CPE matchmatch criteria | cpe:2.3:a:apache:solr:5.3.1:*:*:*:*:*:*:* | ||
5.3.2CPE matchmatch criteria | cpe:2.3:a:apache:solr:5.3.2:*:*:*:*:*:*:* | ||
5.4.0CPE matchmatch criteria | cpe:2.3:a:apache:solr:5.4.0:*:*:*:*:*:*:* | ||
5.4.1CPE matchmatch criteria | cpe:2.3:a:apache:solr:5.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.