Back to search
CVE-2018-1308
Published: Apr 9, 2018
Modified: Sep 17, 2024
PUBLISHED
Description
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Solr | affected 1.2 to 6.6.2affected 7.0.0 to 7.2.1 |
References
DSA-4194
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20180424 [SECURITY] [DLA 1360-1] lucene-solr security update
mailing-list
x_refsource_MLIST
https://issues.apache.org/jira/browse/SOLR-11971
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now