Skip to content
Apache SolrGHSA-mx2h-hf7j-2x3p

Improper Neutralization of Input During Web Page Generation in Apache Solr

Medium6.1CVE-2015-8795 · Published May 17, 2022 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
< 5.1.05.1.0
Details and references

Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2015-8795

More Apache Solr advisories

All Apache Solr
DateAdvisory
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8797Medium6.1fixed in 5.3.1
May 172022Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
CVE-2013-6397Mediumfixed in 4.6.0
May 172022XML Injection in Apache Solr
CVE-2013-6408Mediumfixed in 4.3.1
May 172022Apache Solr UpdateRequestHandler for XML resolves XML External Entities
CVE-2013-6407Mediumfixed in 4.1.0
May 172022Improper Restriction of XML External Entity Reference in Apache Solr
CVE-2012-6612Highfixed in 4.1.0
May 142022Apache Solr insecure inter-node communication
CVE-2017-7660High7.5fixed in 5.5.5, 6.6.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.