CVE-2019-12401XML Entity Expansion in Apache Solr

Severity
7.5HIGHNVD
EPSS
32.8%
top 3.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 10
Latest updateMay 24

Description

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/solr1.3.01.4.1+2
CVEListV5apache/solr1.3.0 to 1.4.1, 3.1.0 to 3.6.2, 4.0.0 to 4.10.4+2

🔴Vulnerability Details

3
GHSA
Apache Solr vulnerable to XML Bomb2022-05-24
OSV
Apache Solr vulnerable to XML Bomb2022-05-24
CVEList
CVE-2019-12401: Solr versions 12019-09-10

📋Vendor Advisories

2
Red Hat
solr: XML resource consumption attack via update handler2019-09-09
Debian
CVE-2019-12401: lucene-solr - Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable ...2019

💬Community

2
Bugzilla
CVE-2019-12401 solr3: solr: XML resource consumption attack via update handler [fedora-all]2020-01-09
Bugzilla
CVE-2019-12401 solr: XML resource consumption attack via update handler2020-01-09
CVE-2019-12401 — XML Entity Expansion in Apache Solr | cvebase