Skip to content

Security advisory for jwt-auth blockunknown#181

Merged
janhoy merged 5 commits into
mainfrom
security-advisory-jwt-blockunknown
May 20, 2026
Merged

Security advisory for jwt-auth blockunknown#181
janhoy merged 5 commits into
mainfrom
security-advisory-jwt-blockunknown

Conversation

@janhoy
Copy link
Copy Markdown
Contributor

@janhoy janhoy commented May 19, 2026

No description provided.

Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new security advisory documenting that the JWT Authentication Plugin's blockUnknown parameter defaults to false in code despite the Reference Guide documenting it as true, advising operators to explicitly set the value and noting an upcoming fix in 9.11/10.1.

Changes:

  • Adds a new advisory file under content/solr/security/ following the existing front-matter + markdown-section convention.
  • Describes affected versions (9.0.0–9.10.1, 10.0.0), conditions for being affected, mitigation, and planned fix.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@janhoy janhoy merged commit 0c7186c into main May 20, 2026
2 checks passed
@janhoy janhoy deleted the security-advisory-jwt-blockunknown branch May 20, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants