Skip to content
Apache SolrGHSA-j8qw-mwmv-28cg

Improper Limitation of a Pathname to a Restricted Directory in Apache Solr

MediumCVE-2013-6397 · Published May 17, 2022 · updated Nov 30, 2024

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
< 4.6.04.6.0
Details and references

More Apache Solr advisories

All Apache Solr
Advisory
Improper Restriction of XML External Entity Reference in Apache Solr
HighMay 17, 2022
XML Injection in Apache Solr
MediumMay 17, 2022
Apache Solr UpdateRequestHandler for XML resolves XML External Entities
MediumMay 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022
Apache Solr insecure inter-node communication
High7.5May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.