Skip to content
Apache SolrGHSA-6cpj-3g83-q2j4

Improper Restriction of XML External Entity Reference in Apache Solr

HighCVE-2012-6612 · Published May 17, 2022 · updated Dec 7, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
< 4.1.04.1.0
Details and references

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.

Severity from
GitHub (reviewed advisory)
Weakness
CWE-611
Also known as
CVE-2012-6612

More Apache Solr advisories

All Apache Solr
DateAdvisory
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8797Medium6.1fixed in 5.3.1
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8795Medium6.1fixed in 5.1.0
May 172022Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
CVE-2013-6397Mediumfixed in 4.6.0
May 172022XML Injection in Apache Solr
CVE-2013-6408Mediumfixed in 4.3.1
May 172022Apache Solr UpdateRequestHandler for XML resolves XML External Entities
CVE-2013-6407Mediumfixed in 4.1.0
May 142022Apache Solr insecure inter-node communication
CVE-2017-7660High7.5fixed in 5.5.5, 6.6.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.