Skip to content
Apache SolrGHSA-ww97-9w65-2crx

Improper Input Validation in Apache Solr

High7.5CVE-2019-17558 · Published Feb 12, 2020 · updated Oct 22, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 5.0.0, < 8.4.08.4.0
>= 6.0.0, < 8.4.08.4.0
>= 7.0.0, < 8.4.08.4.0
>= 8.0.0, < 8.4.08.4.0
Details and references

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-74, CWE-94
Also known as
CVE-2019-17558

More Apache Solr advisories

All Apache Solr
DateAdvisory
Jan 282020Unrestricted upload of file with dangerous type in Apache Solr
CVE-2019-12409Critical9.8fixed in 8.3.0
Aug 12019XML External Entity (XXE) Injection in Apache Solr
CVE-2019-0193High7.2fixed in 8.2.0
Mar 142019Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core
CVE-2017-3164High7.5fixed in 7.7.0
Mar 142019Critical severity vulnerability that affects org.apache.solr:solr-core
CVE-2019-0192Critical9.8fixed in 7.0.0
May 102021Improper permission handling in Apache Solr
CVE-2021-29262High7.5fixed in 8.8.2
Oct 182018Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.