Apache Solr vulnerabilities
2 known vulnerabilities affecting apache/apache_solr.
Total CVEs
2
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2018-11802MEDIUMCVSS 4.3vbefore 7.72020-04-01
CVE-2018-11802 [MEDIUM] CWE-863 CVE-2018-11802: In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all
cvelistv5nvd
CVE-2019-0193HIGHCVSS 7.2KEVPoCvApache Solr all prior to 8.2.02019-08-01
CVE-2019-0193 [HIGH] CWE-94 CVE-2019-0193: In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can co
cvelistv5nvd