Apache SolrGHSA-jq2w-w7v2-69q5
Apache Solr vulnerable to XML Bomb
High7.5CVE-2019-12401 · Published May 24, 2022 · updated Feb 21, 2024
Solr versions prior to 5.0.0 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it?s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.solr:solr-core Maven | < 5.0.0 | 5.0.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-776
- Also known as
- CVE-2019-12401
- nvd.nist.gov/vuln/detail/CVE-2019-12401
- github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-12401-XML%20Bomb-Apache%20Solr
- issues.apache.org/jira/browse/SOLR-13750
- lists.apache.org/thread.html/048ae6e4f84a88e8856f766320b48ad91f9fca2c6f621aa2c40088fe@%3Cdev.lucene.apache.org%3E
- lists.apache.org/thread.html/0ec231c5ed8d242890e21806d25fdd47f80cc47cac278d2fc1c9c579@%3Cdev.lucene.apache.org%3E
- lists.apache.org/thread.html/1c92300643f48f13bc59b15e3f886ba62bae1798c7d4c2e5c1ece09b@%3Cannounce.apache.org%3E
- lists.apache.org/thread.html/521d10a19bfb590f86dff41820ccfb11e92281f233a12c882650931e@%3Cdev.lucene.apache.org%3E
- lists.apache.org/thread.html/60a924662ead9aeea74e8ea128d9ca935f8de925aa71b15ab2787d6a@%3Csolr-user.lucene.apache.org%3E
- lists.apache.org/thread.html/7ab5e95a1a0b4f35ffe53f1eb0cb74b4348b49d41b72ac155b843fa2@%3Cgeneral.lucene.apache.org%3E
- lists.apache.org/thread.html/db8eaca456d03c00a66cbe37548978318d424b9997e3fd7f5c65dffe@%3Cdev.lucene.apache.org%3E
- security.netapp.com/advisory/ntap-20190926-0002
- mail-archives.us.apache.org/mod_mbox/www-announce/201909.mbox/%3CCAECwjAXU4%3DkAo5DeUJw7Kvk67sgCmajAN7LGZQNjbjZ8gv%3DBdw%40mail.gmail.com%3E
- www.openwall.com/lists/oss-security/2019/09/10/1
More Apache Solr advisories
All Apache Solr| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Improper Restriction of XML External Entity Reference in Apache Solr | High | 4.1.0 |
| May 172022 | XML Injection in Apache Solr | Medium | 4.3.1 |
| May 172022 | Apache Solr UpdateRequestHandler for XML resolves XML External Entities | Medium | 4.1.0 |
| May 172022 | Improper Limitation of a Pathname to a Restricted Directory in Apache Solr | Medium | 4.6.0 |
| May 172022 | Improper Neutralization of Input During Web Page Generation in Apache Solr | Medium6.1 | 5.1.0 |
| May 172022 | Improper Neutralization of Input During Web Page Generation in Apache Solr | Medium6.1 | 5.3.1 |