Skip to content
Apache SolrGHSA-2289-pqfq-6wx7

Unrestricted upload of file with dangerous type in Apache Solr

Critical9.8CVE-2019-12409 · Published Jan 28, 2020 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 8.1.1, < 8.3.08.3.0
Details and references

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-434
Also known as
CVE-2019-12409

More Apache Solr advisories

All Apache Solr
DateAdvisory
Feb 122020Improper Input Validation in Apache Solr
CVE-2019-17558High7.5fixed in 8.4.0
Aug 12019XML External Entity (XXE) Injection in Apache Solr
CVE-2019-0193High7.2fixed in 8.2.0
Mar 142019Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core
CVE-2017-3164High7.5fixed in 7.7.0
Mar 142019Critical severity vulnerability that affects org.apache.solr:solr-core
CVE-2019-0192Critical9.8fixed in 7.0.0
Oct 182018Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1
Oct 172018Remote code execution occurs in Apache Solr
CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.