CVE-2018-8010
- EPSS 1.73%
- Veröffentlicht 21.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:05
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files i...
CVE-2018-1308
- EPSS 2.52%
- Veröffentlicht 09.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:35
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order t...
CVE-2017-1000190
- EPSS 0.76%
- Veröffentlicht 17.11.2017 21:29:00
- Zuletzt bearbeitet 12.09.2025 20:08:07
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
CVE-2017-12629
- EPSS 93.78%
- Veröffentlicht 14.10.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is N...
CVE-2017-9803
- EPSS 0.34%
- Veröffentlicht 18.09.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvid...
CVE-2017-3163
- EPSS 5.39%
- Veröffentlicht 30.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possi...
CVE-2017-7660
- EPSS 0.46%
- Veröffentlicht 07.07.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the...
CVE-2015-8797
- EPSS 2.07%
- Veröffentlicht 15.02.2016 02:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
CVE-2015-8796
- EPSS 2.55%
- Veröffentlicht 15.02.2016 02:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
CVE-2015-8795
- EPSS 2.56%
- Veröffentlicht 15.02.2016 02:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related ...