9.8

CVE-2017-12629

Exploit

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

Data is provided by the National Vulnerability Database (NVD)
ApacheSolr Version >= 5.5.0 <= 5.5.4
ApacheSolr Version >= 6.0.0 <= 6.6.1
ApacheSolr Version >= 7.0.0 <= 7.0.1
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
CanonicalUbuntu Linux Version16.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 93.89% 0.999
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

http://openwall.com/lists/oss-security/2017/10/13/1
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/101261
Third Party Advisory
VDB Entry
https://s.apache.org/FJDl
Vendor Advisory
Exploit
Mailing List
https://usn.ubuntu.com/4259-1/
Third Party Advisory
https://www.exploit-db.com/exploits/43009/
Third Party Advisory
Exploit
VDB Entry