CVE-2017-1000190
- EPSS 0.35%
- Veröffentlicht 17.11.2017 21:29:00
- Zuletzt bearbeitet 12.09.2025 20:08:07
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
CVE-2017-12629
- EPSS 93.89%
- Veröffentlicht 14.10.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is N...
CVE-2017-9803
- EPSS 0.34%
- Veröffentlicht 18.09.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvid...
CVE-2017-3163
- EPSS 20.83%
- Veröffentlicht 30.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possi...
CVE-2017-7660
- EPSS 0.46%
- Veröffentlicht 07.07.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the...
CVE-2015-8797
- EPSS 2.07%
- Veröffentlicht 15.02.2016 02:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
CVE-2015-8796
- EPSS 2.55%
- Veröffentlicht 15.02.2016 02:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
CVE-2015-8795
- EPSS 2.56%
- Veröffentlicht 15.02.2016 02:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related ...
CVE-2014-3628
- EPSS 1.92%
- Veröffentlicht 06.01.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
CVE-2012-6612
- EPSS 1.19%
- Veröffentlicht 07.12.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related ...