Back to search
CVE-2013-6408
Published: Dec 7, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2014:0029
vendor-advisory
x_refsource_REDHAT
55542
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20131128 Re: CVE Request: Apache Solr XXE
mailing-list
x_refsource_MLIST
RHSA-2013:1844
vendor-advisory
x_refsource_REDHAT
59372
third-party-advisory
x_refsource_SECUNIA
https://issues.apache.org/jira/browse/SOLR-4881
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now