Apache

Solr

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 21.01.2026 13:41:46
  • Zuletzt bearbeitet 27.01.2026 20:34:13

Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components.  Only deploy...

  • EPSS 0.11%
  • Veröffentlicht 21.01.2026 13:40:24
  • Zuletzt bearbeitet 27.01.2026 20:30:40

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" s...

  • EPSS 0.23%
  • Veröffentlicht 27.01.2025 09:15:14
  • Zuletzt bearbeitet 25.06.2025 16:41:43

Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without aut...

  • EPSS 2.98%
  • Veröffentlicht 27.01.2025 09:15:14
  • Zuletzt bearbeitet 27.06.2025 19:32:29

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API.  Commonly known as a "zipslip", maliciously c...

  • EPSS 0.19%
  • Veröffentlicht 16.10.2024 08:15:05
  • Zuletzt bearbeitet 01.07.2025 20:28:31

Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. Confi...

  • EPSS 94.08%
  • Veröffentlicht 16.10.2024 08:15:05
  • Zuletzt bearbeitet 01.07.2025 20:28:13

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API U...

  • EPSS 82.43%
  • Veröffentlicht 09.02.2024 18:15:08
  • Zuletzt bearbeitet 24.04.2025 16:15:25

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, ...

  • EPSS 0.05%
  • Veröffentlicht 09.02.2024 18:15:08
  • Zuletzt bearbeitet 13.02.2025 18:15:50

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Cloud...

  • EPSS 40.16%
  • Veröffentlicht 09.02.2024 18:15:08
  • Zuletzt bearbeitet 15.05.2025 20:15:28

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was...

  • EPSS 3.09%
  • Veröffentlicht 09.02.2024 18:15:08
  • Zuletzt bearbeitet 15.05.2025 20:15:28

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/prop...