Skip to content

Apache Solr security advisories

31 advisories · 3 critical or high in 12 months · latest Jun 1

31 advisories

DateAdvisory
Jun 1Apache Solr has hardcoded credentials in the Basic Authentication setup tool
CVE-2026-44825High8.1no fix yet
Jan 21Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
CVE-2026-22022High8.2fixed in 9.10.1
Jan 21Apache Solr: Insufficient file-access checking in standalone core-creation requests
CVE-2026-22444High7.1fixed in 9.10.1
Jan 272025Apache Solr Relative Path Traversal vulnerability
CVE-2024-52012Mediumfixed in 9.8.0
Jan 272025Apache Solr vulnerable to Execution with Unnecessary Privileges
CVE-2025-24814Highfixed in 9.8.0
Feb 92024Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
CVE-2023-50386High8.8fixed in 8.11.3, 9.4.1
Feb 92024Apache Solr can leak certain passwords due to System Property redaction logic inconsistencies
CVE-2023-50291High7.5fixed in 8.11.3, 9.3.0
Feb 92024Apache Solr Schema Designer blindly "trusts" all configsets
CVE-2023-50292Lowfixed in 8.11.3, 9.3.0
Jan 152024Apache Solr allows read access to host environmet variables
CVE-2023-50290Medium6.5fixed in 9.3.0
May 242022Apache Solr vulnerable to XML Bomb
CVE-2019-12401High7.5fixed in 5.0.0
May 172022Improper Restriction of XML External Entity Reference in Apache Solr
CVE-2012-6612Highfixed in 4.1.0
May 172022XML Injection in Apache Solr
CVE-2013-6408Mediumfixed in 4.3.1
May 172022Apache Solr UpdateRequestHandler for XML resolves XML External Entities
CVE-2013-6407Mediumfixed in 4.1.0
May 172022Improper Limitation of a Pathname to a Restricted Directory in Apache Solr
CVE-2013-6397Mediumfixed in 4.6.0
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8795Medium6.1fixed in 5.1.0
May 172022Improper Neutralization of Input During Web Page Generation in Apache Solr
CVE-2015-8797Medium6.1fixed in 5.3.1
May 142022Apache Solr insecure inter-node communication
CVE-2017-7660High7.5fixed in 5.5.5, 6.6.0
May 142022Apache Solr Kerberos delegation token functionality flaws
CVE-2017-9803High7.5fixed in 6.6.1
Feb 102022Incorrect Authorization in Apache Solr
CVE-2020-13957Critical9.8fixed in 8.6.3
Feb 92022Incorrect Authorization in Apache Solr
CVE-2018-11802Medium4.3fixed in 6.6.6, 7.7.0
May 102021Improper permission handling in Apache Solr
CVE-2021-29262High7.5fixed in 8.8.2
Feb 122020Improper Input Validation in Apache Solr
CVE-2019-17558High7.5fixed in 8.4.0
Jan 282020Unrestricted upload of file with dangerous type in Apache Solr
CVE-2019-12409Critical9.8fixed in 8.3.0
Aug 12019XML External Entity (XXE) Injection in Apache Solr
CVE-2019-0193High7.2fixed in 8.2.0
Mar 142019Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core
CVE-2017-3164High7.5fixed in 7.7.0
Mar 142019Critical severity vulnerability that affects org.apache.solr:solr-core
CVE-2019-0192Critical9.8fixed in 7.0.0
Oct 182018Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
CVE-2017-3163High7.5fixed in 5.5.4, 6.4.1
Oct 172018Remote code execution occurs in Apache Solr
CVE-2017-12629Critical9.8fixed in 5.5.5, 6.6.2, 7.1.0
Oct 172018There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
CVE-2018-8010Medium5.5fixed in 6.6.4, 7.3.1
Oct 172018There is a XML external entity expansion (XXE) vulnerability in Apache Solr
CVE-2018-1308High7.5fixed in 6.6.3, 7.3.0
Oct 172018XML external entity expansion in org.apache.solr:solr-core
CVE-2018-8026Medium5.5fixed in 6.6.5, 7.4.0
About Apache Solr

Search on Lucene.

Packages watched: org.apache.solr:solr-core (Maven).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.