CVE-2025-24814
- EPSS 0.14%
- Published 27.01.2025 09:15:14
- Last modified 25.06.2025 16:41:43
Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without aut...
CVE-2024-52012
- EPSS 1.35%
- Published 27.01.2025 09:15:14
- Last modified 27.06.2025 19:32:29
Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API. Commonly known as a "zipslip", maliciously c...
CVE-2024-45217
- EPSS 0.15%
- Published 16.10.2024 08:15:05
- Last modified 01.07.2025 20:28:31
Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. Confi...
CVE-2024-45216
- EPSS 93.96%
- Published 16.10.2024 08:15:05
- Last modified 01.07.2025 20:28:13
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API U...
CVE-2023-50386
- EPSS 82.43%
- Published 09.02.2024 18:15:08
- Last modified 24.04.2025 16:15:25
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, ...
CVE-2023-50298
- EPSS 0.03%
- Published 09.02.2024 18:15:08
- Last modified 13.02.2025 18:15:50
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Cloud...
CVE-2023-50292
- EPSS 40.16%
- Published 09.02.2024 18:15:08
- Last modified 15.05.2025 20:15:28
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was...
CVE-2023-50291
- EPSS 0.37%
- Published 09.02.2024 18:15:08
- Last modified 15.05.2025 20:15:28
Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/prop...
CVE-2023-50290
- EPSS 93.07%
- Published 15.01.2024 10:15:26
- Last modified 09.05.2025 21:15:49
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variable...
CVE-2023-44487
- EPSS 94.44%
- Published 10.10.2023 14:15:10
- Last modified 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.