Executive brief
Metacat is data repository software used by researchers to preserve and share scientific data. An unauthenticated attacker can exploit a vulnerability in the search endpoint to bypass access controls and retrieve sensitive configuration files from the Solr backend, such as solrconfig.xml, which may expose internal infrastructure details and aid further attacks.
Technical details
The vulnerability is a parameter injection attack in the MetacatSolrIndex.query method. The client-controlled qt parameter from search requests (e.g., /d1/mn/v2/query/solr/) is forwarded unsanitized through Apache SolrJ to the backend Solr instance. An attacker can inject the /admin/file handler via the qt parameter; even when Solr is hardened with handleSelect=false (Solr 7.0+), SolrJ reformats the request in a way that bypasses this protection. The Solr backend returns the requested core configuration file, which Metacat embeds in an XML processing error response, leaking sensitive internal files. No authentication is required; the attack is network-accessible from any client. The vulnerability is fixed in Metacat 3.4.2 by rejecting queries containing the qt parameter.
Affected products
- NCEAS Metacat before 3.4.2
Timeline
- 2026-09-17: disclosed
- 2026-05-26: patched: Fixed in version 3.4.2