CVE-2025-24814
- EPSS 0.14%
- Veröffentlicht 27.01.2025 09:15:14
- Zuletzt bearbeitet 25.06.2025 16:41:43
Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without aut...
CVE-2024-52012
- EPSS 1.35%
- Veröffentlicht 27.01.2025 09:15:14
- Zuletzt bearbeitet 27.06.2025 19:32:29
Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API. Commonly known as a "zipslip", maliciously c...
CVE-2024-45217
- EPSS 0.15%
- Veröffentlicht 16.10.2024 08:15:05
- Zuletzt bearbeitet 01.07.2025 20:28:31
Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. Confi...
CVE-2024-45216
- EPSS 93.96%
- Veröffentlicht 16.10.2024 08:15:05
- Zuletzt bearbeitet 01.07.2025 20:28:13
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API U...
CVE-2023-50386
- EPSS 82.43%
- Veröffentlicht 09.02.2024 18:15:08
- Zuletzt bearbeitet 24.04.2025 16:15:25
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, ...
CVE-2023-50298
- EPSS 0.03%
- Veröffentlicht 09.02.2024 18:15:08
- Zuletzt bearbeitet 13.02.2025 18:15:50
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Cloud...
CVE-2023-50292
- EPSS 40.16%
- Veröffentlicht 09.02.2024 18:15:08
- Zuletzt bearbeitet 15.05.2025 20:15:28
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was...
CVE-2023-50291
- EPSS 0.37%
- Veröffentlicht 09.02.2024 18:15:08
- Zuletzt bearbeitet 15.05.2025 20:15:28
Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/prop...
CVE-2023-50290
- EPSS 93.07%
- Veröffentlicht 15.01.2024 10:15:26
- Zuletzt bearbeitet 09.05.2025 21:15:49
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variable...
CVE-2023-44487
- EPSS 94.44%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.