Apache

Solr

44 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.35%
  • Published 17.11.2017 21:29:00
  • Last modified 12.09.2025 20:08:07

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

Exploit
  • EPSS 93.89%
  • Published 14.10.2017 23:29:00
  • Last modified 20.04.2025 01:37:25

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is N...

  • EPSS 0.34%
  • Published 18.09.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvid...

  • EPSS 20.83%
  • Published 30.08.2017 14:29:00
  • Last modified 20.04.2025 01:37:25

When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possi...

  • EPSS 0.46%
  • Published 07.07.2017 19:29:00
  • Last modified 20.04.2025 01:37:25

Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the...

  • EPSS 2.07%
  • Published 15.02.2016 02:59:17
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.

  • EPSS 2.55%
  • Published 15.02.2016 02:59:16
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.

  • EPSS 2.56%
  • Published 15.02.2016 02:59:15
  • Last modified 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related ...

  • EPSS 1.92%
  • Published 06.01.2015 15:59:00
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.

  • EPSS 1.19%
  • Published 07.12.2013 21:55:09
  • Last modified 11.04.2025 00:51:21

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related ...