Skip to content
Apache SolrGHSA-45w3-2hvv-pfxq

XML Injection in Apache Solr

MediumCVE-2013-6408 · Published May 17, 2022 · updated Nov 30, 2024

The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
< 4.3.14.3.1
Details and references

More Apache Solr advisories

All Apache Solr
Advisory
Improper Restriction of XML External Entity Reference in Apache Solr
HighMay 17, 2022
Apache Solr UpdateRequestHandler for XML resolves XML External Entities
MediumMay 17, 2022
Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
MediumMay 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022
Apache Solr insecure inter-node communication
High7.5May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.