CVE-2018-8010
published 2018-05-21CVE-2018-8010: This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml…
PriorityP434medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
3.92%
89.2th percentile
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resources below the Solr instance directory (using Solr's ResourceLoader); usage of absolute URLs is denied. Keep in mind, that external entities and XInclude are explicitly supported to better structure config files in large installations. Before Solr 6 this was no problem, as config files were not accessible through the APIs.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | solr | 6.0.0 – 6.6.3 | — |
| apache | solr | 7.0.0 – 7.3.0 | — |
| apache_software_foundation | apache_solr | — | — |
| debian | lucene-solr | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
ghsa·2018-10-17
CVE-2018-8010 [MEDIUM] CWE-611 There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resources
OSV
There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
osv·2018-10-17
CVE-2018-8010 [MEDIUM] There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resources
Red Hat
solr: XML external entity expansion in config files allows attackers to read arbitrary files
vendor_redhat·2018-05-21·CVSS 5.5
CVE-2018-8010 [MEDIUM] CWE-611 solr: XML external entity expansion in config files allows attackers to read arbitrary files
solr: XML external entity expansion in config files allows attackers to read arbitrary files
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resou
Debian
CVE-2018-8010: lucene-solr - This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an X...
vendor_debian·2018·CVSS 5.5
CVE-2018-8010 [MEDIUM] CVE-2018-8010: lucene-solr - This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an X...
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resources below the Solr instance directory (using Solr's ResourceLoader); usage of absolute URLs i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8010 solr: XML external entity expansion in config files allows attackers to read arbitrary files
bugzilla·2018-05-22·CVSS 5.5
CVE-2018-8010 [MEDIUM] CVE-2018-8010 solr: XML external entity expansion in config files allows attackers to read arbitrary files
CVE-2018-8010 solr: XML external entity expansion in config files allows attackers to read arbitrary files
Apache Solr versions 6.0.0 to 6.6.3 and 7.0.0 to 7.3.0 have an XML external entity expansion (XXE) vulnerability in config files (solrconfig.xml, schema.xml, managed-schema). An attacker could exploit this to read arbitrary local files from the Solr server or the internal network.
External References:
http://www.openwall.com/lists/oss-security/2018/05/21/4
Upstream Issue:
https://issues.apache.org/jira/browse/SOLR-12316
Discussion:
Created solr3 tracking bugs for this issue:
Affects: fedora-all [bug 1581038]
Bugzilla
CVE-2018-8010 solr3: solr: XML external entity expansion in config files allows attackers to read arbitrary files [fedora-all]
bugzilla·2018-05-22·CVSS 5.5
CVE-2018-8010 [MEDIUM] CVE-2018-8010 solr3: solr: XML external entity expansion in config files allows attackers to read arbitrary files [fedora-all]
CVE-2018-8010 solr3: solr: XML external entity expansion in config files allows attackers to read arbitrary files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
http://www.securityfocus.com/bid/104239https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://mail-archives.apache.org/mod_mbox/www-announce/201805.mbox/%3C08a801d3f0f9%24df46d300%249dd47900%24%40apache.org%3Ehttp://www.securityfocus.com/bid/104239https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://mail-archives.apache.org/mod_mbox/www-announce/201805.mbox/%3C08a801d3f0f9%24df46d300%249dd47900%24%40apache.org%3E
2018-05-21
Published