CVE-2014-3628
published 2015-01-06CVE-2014-3628: Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
4.70%
90.9th percentile
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| debian | lucene-solr | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
solr: Cross-site scripting (XSS) vulnerability via the fieldvaluecache object
vendor_redhat·2014-12-29·CVSS 4.3
CVE-2014-3628 [MEDIUM] CWE-79 solr: Cross-site scripting (XSS) vulnerability via the fieldvaluecache object
solr: Cross-site scripting (XSS) vulnerability via the fieldvaluecache object
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
Package: solr-core (Red Hat JBoss Data Grid 6.3.1) - Will not fix
Package: solr-core (Red Hat JBoss Data Virtualization 6.0.0) - Will not fix
Package: solr-core (Red Hat JBoss Fuse Service Works 6.0.0) - Will not fix
Debian
CVE-2014-3628: lucene-solr - Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in ...
vendor_debian·2014·CVSS 4.3
CVE-2014-3628 [MEDIUM] CVE-2014-3628: lucene-solr - Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in ...
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Kernel
wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker()
kernel_security·2022-10-21·CVSS 6.6
CVE-2022-3628 [MEDIUM] wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker()
wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker()
This patch fixes an intra-object buffer overflow in brcmfmac that occurs
when the device provides a 'bsscfgidx' equal to or greater than the
buffer size. The patch adds a check that leads to a safe failure if that
is the case.
This fixes CVE-2022-3628.
UBSAN: array-index-out-of-bounds in drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c
index 52 is out of range for type 'brcmf_if *[16]'
CPU: 0 PID: 1898 Comm: kworker/0:2 Tainted: G O 5.14.0+ #132
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014
Workqueue: events brcmf_fweh_event_worker
Call Trace:
dump_stack_lvl+0x57/0x7d
ubsan_epilogue+0x5/0x40
__ubsan_handle_out_of_bounds+0x69/0x80
? memcp
GHSA
Improper Neutralization of Input During Web Page Generation in Apache Solr
ghsa·2022-05-17
CVE-2014-3628 [MEDIUM] CWE-79 Improper Neutralization of Input During Web Page Generation in Apache Solr
Improper Neutralization of Input During Web Page Generation in Apache Solr
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
OSV
Improper Neutralization of Input During Web Page Generation in Apache Solr
osv·2022-05-17
CVE-2014-3628 [MEDIUM] Improper Neutralization of Input During Web Page Generation in Apache Solr
Improper Neutralization of Input During Web Page Generation in Apache Solr
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
No detection rules found.
No public exploits indexed.
2015-01-06
Published