CVE Database
/

CVE-2019-0192

Back to search

CVE-2019-0192

Published: Mar 7, 2019

Modified: Sep 16, 2024

PUBLISHED

Description

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

VendorProductVersions

Apache Software Foundation

Apache Solr

affected
Apache Solr 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5

References

107318
vdb-entry
x_refsource_BID
RHSA-2019:2413
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now