Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-16671

Explicitly call out library permissions for config-edit

    XMLWordPrintableJSON

Details

    Description

      A lot of security questions arise from various options to add custom libraries via a solrconfig.xml. When using the recommended solr auth plugin, a user requires the config-edit permission to edit this file. And custom libraries will only be used when the solrconfig is trusted by Solr.

      Right now the  config-edit permission documentation does not explicitly spell out that the permission gives users the ability to install any custom library to Solr. We should fix this to reduce confusion around RCEs.

      With our antora docs, I suggest we backport this documentation change to 9.0 and 9.1, and also update 8.11 for the next patch release.

      Attachments

        Issue Links

          Activity

            People

              houston Houston Putman
              houston Houston Putman
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m