Skip to content
Apache SolrGHSA-xhcq-fv7x-grr2

Critical severity vulnerability that affects org.apache.solr:solr-core

Critical9.8CVE-2019-0192 · Published Mar 14, 2019 · updated Feb 17, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.solr:solr-core
Maven
>= 5.0.0, < 7.0.07.0.0
>= 6.0.0, < 7.0.07.0.0
Details and references

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2019-0192

More Apache Solr advisories

All Apache Solr
DateAdvisory
Mar 142019Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core
CVE-2017-3164High7.5fixed in 7.7.0
Aug 12019XML External Entity (XXE) Injection in Apache Solr
CVE-2019-0193High7.2fixed in 8.2.0
Oct 182018Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1
Oct 172018Remote code execution occurs in Apache Solr
CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0
Oct 172018There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
CVE-2018-8010Medium5.5fixed in 6.6.4, 7.3.1
Oct 172018There is a XML external entity expansion (XXE) vulnerability in Apache Solr
CVE-2018-1308High7.5fixed in 6.6.3, 7.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.