This module provides support for creating searches using the Apache Solr search engine and the Search API Drupal module.
The module doesn't sufficiently protect certain routes from CSRF attacks.
This vulnerability is mitigated by the fact that a site admin would have to perform further steps after the attack for it to have any effect.
Install the latest version:
- If you use the Search API Solr module for Drupal 8+, upgrade to Search API Solr 4.3.10.
We also recommend checking your Solr configuration for any unintended changes.
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team