Skip to content
Apache SolrGHSA-vrh8-27q8-fr8f

Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core

High7.5CVE-2017-3164 · Published Mar 14, 2019 · updated Apr 16, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 1.3.0, < 7.7.07.7.0
Details and references

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2017-3164

More Apache Solr advisories

All Apache Solr
DateAdvisory
Mar 142019Critical severity vulnerability that affects org.apache.solr:solr-core
CVE-2019-0192Critical9.8fixed in 7.0.0
Aug 12019XML External Entity (XXE) Injection in Apache Solr
CVE-2019-0193High7.2fixed in 8.2.0
Oct 182018Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1
Oct 172018Remote code execution occurs in Apache Solr
CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0
Oct 172018There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
CVE-2018-8010Medium5.5fixed in 6.6.4, 7.3.1
Oct 172018There is a XML external entity expansion (XXE) vulnerability in Apache Solr
CVE-2018-1308High7.5fixed in 6.6.3, 7.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.