Apache SolrGHSA-3pph-2595-cgfh
There is a XML external entity expansion (XXE) vulnerability in Apache Solr
High7.5CVE-2018-1308 · Published Oct 17, 2018 · updated Mar 4, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.solr:solr-core Maven | >= 1.2, < 6.6.3 | 6.6.3 |
| >= 7.0.0, < 7.3.0 | 7.3.0 |
Details and references
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-611
- Also known as
- CVE-2018-1308
- nvd.nist.gov/vuln/detail/CVE-2018-1308
- github.com/apache/lucene-solr/commit/3530397f1777332872eac2760f9aa0e2ae1d7450
- github.com/apache/lucene-solr/commit/739a7933
- github.com/apache/lucene-solr/commit/dd3be31f7062dcb2f3b2d7f0e89df29e197dee63
- github.com/advisories/GHSA-3pph-2595-cgfh
- issues.apache.org/jira/browse/SOLR-11971
- lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E
- lists.debian.org/debian-lts-announce/2018/04/msg00025.html
- mail-archives.apache.org/mod_mbox/www-announce/201804.mbox/%3C000001d3cf68%245ac69af0%241053d0d0%24%40apache.org%3E
- www.debian.org/security/2018/dsa-4194
More Apache Solr advisories
All Apache Solr| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 172018 | XML external entity expansion in org.apache.solr:solr-core CVE-2018-8026Medium5.5fixed in 6.6.5, 7.4.0 | Medium5.5 | 6.6.5, 7.4.0 |
| Oct 172018 | There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files CVE-2018-8010Medium5.5fixed in 6.6.4, 7.3.1 | Medium5.5 | 6.6.4, 7.3.1 |
| Oct 172018 | Remote code execution occurs in Apache Solr CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0 | Critical9.8 | 5.5.5, 6.6.2, 7.1.0 |
| Oct 182018 | Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1 | High7.5 | 5.5.4, 6.4.1 |
| Mar 142019 | Critical severity vulnerability that affects org.apache.solr:solr-core CVE-2019-0192Critical9.8fixed in 7.0.0 | Critical9.8 | 7.0.0 |
| Mar 142019 | Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core CVE-2017-3164High7.5fixed in 7.7.0 | High7.5 | 7.7.0 |