Apache SolrGHSA-3gm7-v7vw-866c
XML External Entity (XXE) Injection in Apache Solr
High7.2CVE-2019-0193 · Published Aug 1, 2019 · updated Oct 22, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.solr:solr-core Maven | < 8.2.0 | 8.2.0 |
Details and references
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2019-0193
- nvd.nist.gov/vuln/detail/CVE-2019-0193
- github.com/apache/lucene-solr/commit/02c693f3713add1b4891cbaa87127de3a55c10f7
- github.com/apache/lucene-solr
- lists.apache.org/thread.html/r19d23e8640236a3058b4d6c23e5cd663fde182255f5a9d63e0606a66@%3Cdev.lucene.apache.org%3E
- lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1%40%3Ccommits.druid.apache.org%3E
- lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1@%3Ccommits.druid.apache.org%3E
- lists.apache.org/thread.html/r339865b276614661770c909be1dd7e862232e3ef0af98bfd85686b51%40%3Cdev.lucene.apache.org%3E
- lists.apache.org/thread.html/r339865b276614661770c909be1dd7e862232e3ef0af98bfd85686b51@%3Cdev.lucene.apache.org%3E
- lists.apache.org/thread.html/r33aed7ad4ee9833c4190a44e2b106efd2deb19504b85e012175540f6%40%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/r33aed7ad4ee9833c4190a44e2b106efd2deb19504b85e012175540f6@%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/r3da74965aba2b5f5744b7289ad447306eeb2940c872801819faa9314%40%3Cusers.solr.apache.org%3E
- lists.apache.org/thread.html/r3da74965aba2b5f5744b7289ad447306eeb2940c872801819faa9314@%3Cusers.solr.apache.org%3E
- lists.apache.org/thread.html/r95df34bb158375948da82b4dfe9a1b5d528572d586584162f8f5aeef%40%3Cusers.solr.apache.org%3E
- lists.apache.org/thread.html/r95df34bb158375948da82b4dfe9a1b5d528572d586584162f8f5aeef@%3Cusers.solr.apache.org%3E
- lists.apache.org/thread.html/rb34d820c21f1708c351f9035d6bc7daf80bfb6ef99b34f7af1d2f699%40%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/rb34d820c21f1708c351f9035d6bc7daf80bfb6ef99b34f7af1d2f699@%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/rc400db37710ee79378b6c52de3640493ff538c2beb41cefdbbdf2ab8%40%3Ccommits.submarine.apache.org%3E
- lists.apache.org/thread.html/rc400db37710ee79378b6c52de3640493ff538c2beb41cefdbbdf2ab8@%3Ccommits.submarine.apache.org%3E
- lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
- lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E
- lists.debian.org/debian-lts-announce/2019/10/msg00013.html
- lists.debian.org/debian-lts-announce/2020/08/msg00025.html
- snyk.io/vuln/SNYK-JAVA-ORGAPACHESOLR-536063
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0193
- issues.apache.org/jira/browse/SOLR-13669
- lists.apache.org/thread.html/1addbb49a1fc0947fb32ca663d76d93cfaade35a4848a76d4b4ded9c%40%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/1addbb49a1fc0947fb32ca663d76d93cfaade35a4848a76d4b4ded9c@%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/42cc4d334ba33905b872a0aa00d6a481391951c8b1450f01b077ce74%40%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/42cc4d334ba33905b872a0aa00d6a481391951c8b1450f01b077ce74@%3Cissues.lucene.apache.org%3E
- lists.apache.org/thread.html/55880d48e38ba9e8c41a3b9e41051dbfdef63b86b0cfeb32967edf03%40%3Cissues.lucene.apache.org%3E
More Apache Solr advisories
All Apache Solr| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 142019 | Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core CVE-2017-3164High7.5fixed in 7.7.0 | High7.5 | 7.7.0 |
| Mar 142019 | Critical severity vulnerability that affects org.apache.solr:solr-core CVE-2019-0192Critical9.8fixed in 7.0.0 | Critical9.8 | 7.0.0 |
| Jan 282020 | Unrestricted upload of file with dangerous type in Apache Solr CVE-2019-12409Critical9.8fixed in 8.3.0 | Critical9.8 | 8.3.0 |
| Feb 122020 | Improper Input Validation in Apache Solr CVE-2019-17558High7.5fixed in 8.4.0 | High7.5 | 8.4.0 |
| Oct 182018 | Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1 | High7.5 | 5.5.4, 6.4.1 |
| Oct 172018 | Remote code execution occurs in Apache Solr CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0 | Critical9.8 | 5.5.5, 6.6.2, 7.1.0 |