⚠ Actively exploited
Added to CISA KEV on 2021-12-10. Federal agencies required to patch by 2022-06-10. Required action: Apply updates per vendor instructions..

CVE-2019-0193Code Injection in Apache Solr

Severity
7.2HIGHNVD
EPSS
93.4%
top 0.18%
CISA KEV
KEV
Added 2021-12-10
Due 2022-06-10
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 1
KEV addedDec 10
KEV dueJun 10
Latest updateFeb 21
CISA Required Action: Apply updates per vendor instructions.

Description

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System pr

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDapache/solr8.1.08.1.2+1
CVEListV5apache/apache_solrApache Solr all prior to 8.2.0

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

5
CVEList
CVE-2019-0193: In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the who2019-08-01
GHSA
XML External Entity (XXE) Injection in Apache Solr2019-08-01
OSV
CVE-2019-0193: In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the who2019-08-01
OSV
XML External Entity (XXE) Injection in Apache Solr2019-08-01
VulnCheck
Apache Solr DataImportHandler Code Injection Vulnerability2019

💥Exploits & PoCs

1
Nuclei
Apache Solr DataImportHandler <8.2.0 - Remote Code Execution

🔍Detection Rules

1
Suricata
ET EXPLOIT Solr DataImport Handler RCE (CVE-2019-0193)2021-06-08

📋Vendor Advisories

4
Ubuntu
Apache Solr vulnerability2025-02-21
CISA
Apache Solr DataImportHandler Code Injection Vulnerability2021-12-10
Red Hat
solr: Remote Code Execution via DataImportHandler2019-07-31
Debian
CVE-2019-0193: lucene-solr - In Apache Solr, the DataImportHandler, an optional but popular module to pull in...2019

💬Community

3
HackerOne
Remote Code Execution on █████████2020-09-03
Bugzilla
CVE-2019-0193 solr3: solr: Remote Code Execution via DataImportHandler [fedora-all]2019-08-02
Bugzilla
CVE-2019-0193 solr: Remote Code Execution via DataImportHandler2019-08-01
CVE-2019-0193 — Code Injection in Apache Solr | cvebase