Unrestricted upload of file with dangerous type in Apache Solr
Critical9.8CVE-2019-12409 · Published Jan 28, 2020 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.solr:solr-core Maven | >= 8.1.1, < 8.3.0 | 8.3.0 |
Details and references
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-434
- Also known as
- CVE-2019-12409
- nvd.nist.gov/vuln/detail/CVE-2019-12409
- github.com/github/advisory-review/pull/12462
- github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-12409-RCE%20Vulnerability%20Due%20to%20Bad%20Defalut%20Config-Apache%20Solr
- issues.apache.org/jira/browse/SOLR-13647
- lists.apache.org/thread.html/47e112035b4aa67ece3b75dbcd1b9c9212895b9dfe2a71f6f7c174e2@%3Cannounce.apache.org%3E
- lists.apache.org/thread.html/6640c7e370fce2b74e466a605a46244ccc40666ad9e3064a4e04a85d@%3Csolr-user.lucene.apache.org%3E
- lists.apache.org/thread.html/925cdb49ceae78baddb45da7beb9b4d2b1ddc4a8e318c65e91fb4e87@%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/a044eae4f6f5b0160ece5bf9cc4c0dad90ce7dd9bb210a9dc50b54be@%3Cgeneral.lucene.apache.org%3E
- lists.apache.org/thread.html/ce7c0b456b15f6c7518adefa54ec948fed6de8e951a2584500c1e541@%3Cissues.lucene.apache.org%3E
- support.f5.com/csp/article/K23720587?utm_source=f5support&utm_medium=RSS
More Apache Solr advisories
All Apache Solr| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 122020 | Improper Input Validation in Apache Solr CVE-2019-17558High7.5fixed in 8.4.0 | High7.5 | 8.4.0 |
| Aug 12019 | XML External Entity (XXE) Injection in Apache Solr CVE-2019-0193High7.2fixed in 8.2.0 | High7.2 | 8.2.0 |
| Mar 142019 | Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core CVE-2017-3164High7.5fixed in 7.7.0 | High7.5 | 7.7.0 |
| Mar 142019 | Critical severity vulnerability that affects org.apache.solr:solr-core CVE-2019-0192Critical9.8fixed in 7.0.0 | Critical9.8 | 7.0.0 |
| Oct 182018 | Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1 | High7.5 | 5.5.4, 6.4.1 |
| Oct 172018 | Remote code execution occurs in Apache Solr CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0 | Critical9.8 | 5.5.5, 6.6.2, 7.1.0 |