Skip to content
Apache SolrGHSA-3pph-2595-cgfh

There is a XML external entity expansion (XXE) vulnerability in Apache Solr

High7.5CVE-2018-1308 · Published Oct 17, 2018 · updated Mar 4, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 1.2, < 6.6.36.6.3
>= 7.0.0, < 7.3.07.3.0
Details and references

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-611
Also known as
CVE-2018-1308

More Apache Solr advisories

All Apache Solr
DateAdvisory
Oct 172018XML external entity expansion in org.apache.solr:solr-core
CVE-2018-8026Medium5.5fixed in 6.6.5, 7.4.0
Oct 172018There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
CVE-2018-8010Medium5.5fixed in 6.6.4, 7.3.1
Oct 172018Remote code execution occurs in Apache Solr
CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0
Oct 182018Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1
Mar 142019Critical severity vulnerability that affects org.apache.solr:solr-core
CVE-2019-0192Critical9.8fixed in 7.0.0
Mar 142019Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core
CVE-2017-3164High7.5fixed in 7.7.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.