CVE-2017-3163
published 2017-08-30CVE-2017-3163: When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name…
PriorityP350high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
6.56%
93.1th percentile
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | solr | <= 5.5.3 | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache | solr | — | — |
| apache_software_foundation | apache_solr | — | — |
| apache_software_foundation | apache_solr | — | — |
| debian | lucene-solr | < lucene-solr 3.6.2+dfsg-11 (bookworm) | lucene-solr 3.6.2+dfsg-11 (bookworm) |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_redhat8.8HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
osv·2018-10-18
CVE-2017-3163 [HIGH] Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
GHSA
Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
ghsa·2018-10-18
CVE-2017-3163 [HIGH] CWE-22 Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
OSV
CVE-2017-3163: When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name
osv·2017-08-30·CVSS 7.5
CVE-2017-3163 [HIGH] CVE-2017-3163: When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
Red Hat
chromium-browser: out-of-bounds access in v8
vendor_redhat·2017-09-21·CVSS 8.8
CVE-2017-5122 [HIGH] CWE-119 chromium-browser: out-of-bounds access in v8
chromium-browser: out-of-bounds access in v8
Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.
Red Hat
chromium-browser: out-of-bounds access in v8
vendor_redhat·2017-09-21·CVSS 8.8
CVE-2017-5121 [HIGH] CWE-119 chromium-browser: out-of-bounds access in v8
chromium-browser: out-of-bounds access in v8
Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.
Red Hat
chromium-browser: heap buffer overflow in skia
vendor_redhat·2017-09-05·CVSS 8.8
CVE-2017-5113 [HIGH] chromium-browser: heap buffer overflow in skia
chromium-browser: heap buffer overflow in skia
Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: type confusion in v8
vendor_redhat·2017-09-05·CVSS 8.8
CVE-2017-5115 [HIGH] chromium-browser: type confusion in v8
chromium-browser: type confusion in v8
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
Red Hat
chromium-browser: use after free in pdfium
vendor_redhat·2017-09-05·CVSS 8.8
CVE-2017-5111 [HIGH] chromium-browser: use after free in pdfium
chromium-browser: use after free in pdfium
A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
Red Hat
chromium-browser: heap buffer overflow in webgl
vendor_redhat·2017-09-05·CVSS 8.8
CVE-2017-5112 [HIGH] chromium-browser: heap buffer overflow in webgl
chromium-browser: heap buffer overflow in webgl
Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Red Hat
chromium-browser: use of uninitialized value in skia
vendor_redhat·2017-09-05·CVSS 4.3
CVE-2017-5119 [MEDIUM] chromium-browser: use of uninitialized value in skia
chromium-browser: use of uninitialized value in skia
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Red Hat
chromium-browser: use of uninitialized value in skia
vendor_redhat·2017-09-05·CVSS 6.5
CVE-2017-5117 [MEDIUM] chromium-browser: use of uninitialized value in skia
chromium-browser: use of uninitialized value in skia
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Red Hat
chromium-browser: bypass of content security policy in blink
vendor_redhat·2017-09-05·CVSS 4.3
CVE-2017-5118 [MEDIUM] chromium-browser: bypass of content security policy in blink
chromium-browser: bypass of content security policy in blink
Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: type confusion in v8
vendor_redhat·2017-09-05·CVSS 8.8
CVE-2017-5116 [HIGH] chromium-browser: type confusion in v8
chromium-browser: type confusion in v8
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Red Hat
chromium-browser: potential https downgrade during redirect navigation
vendor_redhat·2017-09-05·CVSS 6.5
CVE-2017-5120 [MEDIUM] chromium-browser: potential https downgrade during redirect navigation
chromium-browser: potential https downgrade during redirect navigation
Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted HTML page. In other words, Chrome could transmit cleartext even though the user had entered an https URL, because of a misdesigned workaround for cases where the domain name in a URL almost matches the domain name in an X.509 server certificate (but differs in the initial "www." substring).
Red Hat
chromium-browser: memory lifecycle issue in pdfium
vendor_redhat·2017-09-05·CVSS 8.8
CVE-2017-5114 [HIGH] chromium-browser: memory lifecycle issue in pdfium
chromium-browser: memory lifecycle issue in pdfium
Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
Red Hat
solr: Directory traversal via Index Replication HTTP API
vendor_redhat·2017-02-15·CVSS 7.5
CVE-2017-3163 [HIGH] CWE-22 solr: Directory traversal via Index Replication HTTP API
solr: Directory traversal via Index Replication HTTP API
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
Package: solr-core (Red Hat JBoss Data Grid 6) - Out of support scope
Package: solr-core (Red Hat JBoss Data Virtualization 6) - Not affected
Package: camel (Red Hat JBoss Fuse 6) - Not affected
Package
Debian
CVE-2017-3163: lucene-solr - When using the Index Replication feature, Apache Solr nodes can pull index files...
vendor_debian·2017·CVSS 7.5
CVE-2017-3163 [HIGH] CVE-2017-3163: lucene-solr - When using the Index Replication feature, Apache Solr nodes can pull index files...
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
Scope: local
bookworm: resolved (fixed in 3.6.2+dfsg-11)
bullseye: resolved (fixed in 3.6.2+dfsg-11)
forky: resolved (fixed in 3.6.2+dfsg-11)
sid: resolved (fixed in 3.6.2+dfsg-11)
trixie: resolved (fixed in 3.6.2+dfsg-11)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2018:1447https://access.redhat.com/errata/RHSA-2018:1448https://access.redhat.com/errata/RHSA-2018:1449https://access.redhat.com/errata/RHSA-2018:1450https://access.redhat.com/errata/RHSA-2018:1451https://lists.apache.org/thread.html/a6a33a186f293f9f9aecf3bd39c76252bfc49a79de4321dd2a53b488%40%3Csolr-user.lucene.apache.org%3Ehttps://www.debian.org/security/2018/dsa-4124https://access.redhat.com/errata/RHSA-2018:1447https://access.redhat.com/errata/RHSA-2018:1448https://access.redhat.com/errata/RHSA-2018:1449https://access.redhat.com/errata/RHSA-2018:1450https://access.redhat.com/errata/RHSA-2018:1451https://lists.apache.org/thread.html/a6a33a186f293f9f9aecf3bd39c76252bfc49a79de4321dd2a53b488%40%3Csolr-user.lucene.apache.org%3Ehttps://www.debian.org/security/2018/dsa-4124
2017-08-30
Published