### [CVE-2021-29943](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29943) ![](https://img.shields.io/static/v1?label=Product&message=Apache%20Solr&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=Apache%20Solr%3C%208.8.2%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-863%20Incorrect%20Authorization&color=brighgreen) ### Description When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/GGStudy-DDUp/2021hvv_vul - https://github.com/YinWC/2021hvv_vul - https://github.com/kenlavbah/log4jnotes