Vulnerability record · CVE-2024-45216 · published 16 October 2024
CVE-2024-45216: Apache Solr PKIAuthenticationPlugin authentication bypass via fake URL path ending
Apache · Solr
Apache Solr instances using the PKIAuthenticationPlugin, enabled by default when Solr Authentication is used, can be bypassed by appending a fake path ending to any Solr API URL. The fake ending is stripped internally after authentication but before API routing, so requests skip authentication while still reaching the intended API path. This affects Solr 5.3.0 before 8.11.4 and 9.0.0 before 9.7.0.
Description
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, default-enabled vulnerable component, and very high EPSS probability make this an urgent patch.
What it is
Apache Solr instances using the PKIAuthenticationPlugin, enabled by default when Solr Authentication is used, can be bypassed by appending a fake path ending to any Solr API URL. The fake ending is stripped internally after authentication but before API routing, so requests skip authentication while still reaching the intended API path. This affects Solr 5.3.0 before 8.11.4 and 9.0.0 before 9.7.0.
Impact
An unauthenticated attacker can reach Solr APIs that should require authentication, gaining full read and write access to indexed data and administrative functionality. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network via HTTP requests to the Solr API; no authentication is required because the flaw itself bypasses authentication, and no user interaction is needed. Any Solr instance with authentication enabled and the default PKIAuthenticationPlugin is exposed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.917 (99.8th percentile), indicating likely active exploitation interest. References are limited to the vendor advisory and an oss-security mailing list post, with no public exploit tag.
What to do
- Upgrade Apache Solr to 9.7.0 or 8.11.4, which fix the issue.
- If immediate upgrade is not possible, restrict network access to Solr API ports to trusted hosts only.
- Verify that Solr authentication is actually enforced by testing a request with a fake path ending against a protected endpoint.
- Review Solr access logs for requests containing suspicious trailing path segments that do not match known API routes.
Detection
- Search Solr request logs for API paths with unexpected trailing segments that are not valid Solr endpoints.
- Alert on successful responses to protected Solr API paths from clients that did not present authentication credentials.
- Monitor for anomalous administrative API calls, such as config or collection changes, originating from unauthenticated or unexpected sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-45216 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-45216), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.