Package impact

java Maven / org.apache.solr:solr-core

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2017-12629 critical 9.8 9.8 9y ago Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener … debianubunturedhatjava+1
CVE-2017-9803 high 7.5 7.5 9y ago Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this… debianjavaapache
CVE-2017-3163 high 7.5 7.5 9y ago When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1… debianjavaapache
CVE-2017-7660 high 7.5 7.5 9y ago Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster a… debianjavaapache
CVE-2012-6612 high 7.5 13y ago The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaratio… debianjavaapache
CVE-2013-6408 medium 6.4 13y ago The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an ex… debianjavaapache
CVE-2013-6407 medium 6.4 13y ago The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity r… debianjavaapache
CVE-2015-8797 medium 6.1 6.1 10y ago Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HT… debianjavaapache
CVE-2015-8795 medium 6.1 6.1 10y ago Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled duri… debianjavaapache
CVE-2021-29262 medium 5.5 5y ago When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only us… archdebianjava
CVE-2013-6397 medium 4.3 13y ago Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/selec… debianjavaapache
CVE-2019-17558 unknown 1.5 6y ago The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. debianjava
CVE-2019-0193 unknown 1.5 7y ago The optional Apache Solr module DataImportHandler contains a code injection vulnerability. debianjava
CVE-2026-22444 unknown 4mo ago The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths … debianjava
CVE-2026-22022 unknown 4mo ago Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict… debianjava
CVE-2025-24814 unknown 1y ago Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "u… debianjava
CVE-2024-52012 unknown 1y ago Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload"… debianjava
CVE-2023-50386 unknown 2y ago Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This iss… debianjava
CVE-2023-50291 unknown 2y ago Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Sol… debianjava
CVE-2023-50292 unknown 2y ago Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2… debianjava
CVE-2023-50290 unknown 2y ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. U… debianjava
CVE-2019-12401 unknown 4y ago Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY t… debianjava
CVE-2020-13957 unknown 4y ago Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that… debianjava
CVE-2018-11802 unknown 4y ago In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does … debianjava
CVE-2019-12409 unknown 6y ago The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use… debianjava
CVE-2017-3164 unknown 7y ago Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the se… debianjava
CVE-2019-0192 unknown 7y ago In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take… debianjava
CVE-2018-8010 unknown 8y ago This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinc… debianjava
CVE-2018-1308 unknown 8y ago This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be u… debianjava
CVE-2018-8026 unknown 8y ago This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIK… debianjava