Skip to content
Apache SolrGHSA-jq2w-w7v2-69q5

Apache Solr vulnerable to XML Bomb

High7.5CVE-2019-12401 · Published May 24, 2022 · updated Feb 21, 2024

Solr versions prior to 5.0.0 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it?s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
< 5.0.05.0.0
Details and references

More Apache Solr advisories

All Apache Solr
Advisory
Improper Restriction of XML External Entity Reference in Apache Solr
HighMay 17, 2022
XML Injection in Apache Solr
MediumMay 17, 2022
Apache Solr UpdateRequestHandler for XML resolves XML External Entities
MediumMay 17, 2022
Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
MediumMay 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022
Improper Neutralization of Input During Web Page Generation in Apache Solr
Medium6.1May 17, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.