Apache Solr vulnerabilities
47 known vulnerabilities affecting apache/solr.
Total CVEs
47
CISA KEV
3
actively exploited
Public exploits
10
Exploited in wild
10
Severity breakdown
CRITICAL10HIGH21MEDIUM15LOW1
Vulnerabilities
Page 2 of 3
CVE-2020-13941P3HIGHCVSS 8.8fixed in 8.6.02020-08-17
CVE-2020-13941 [HIGH] CWE-20 CVE-2020-13941: Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. T
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e
nvd
CVE-2026-22022P3HIGHCVSS 8.2≥ 5.3.0, < 9.10.12026-01-21
CVE-2026-22022 [HIGH] CWE-285 CVE-2026-22022: Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin
Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components. Only deployments that meet all of the following criteria are impacted by this vulnerability:
* Use of Solr's "Rule
nvd
CVE-2023-50292P3HIGHCVSS 7.5≥ 6.0.0, < 8.11.3≥ 9.0.0, < 9.4.12024-02-09
CVE-2023-50292 [HIGH] CWE-732 CVE-2023-50292: Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0.
The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets.
However, when t
nvd
CVE-2024-45217P3HIGHCVSS 8.1≥ 6.6.0, < 8.11.4≥ 9.0.0, < 9.7.02024-10-16
CVE-2024-45217 [HIGH] CWE-1188 CVE-2024-45217: Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are c
Insecure Default Initialization of Resource vulnerability in Apache Solr.
New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata.
ConfigSets that do not contain the flag are trusted implicitly if the metadata is missing, therefore this le
nvd
CVE-2017-3163P3HIGHCVSS 7.5≤ 5.5.3v6.0.0+6 more2017-08-30
CVE-2017-3163 [HIGH] CWE-22 CVE-2017-3163: When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leade
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server proc
nvd
CVE-2021-29262P3HIGHCVSS 7.5fixed in 8.8.22021-04-13
CVE-2021-29262 [HIGH] CWE-522 CVE-2021-29262: When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParams
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the s
nvd
CVE-2012-6612P3HIGHCVSS 7.5≤ 4.0.0v4.0.02013-12-07
CVE-2012-6612 [HIGH] CVE-2012-6612: The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows r
The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.
nvd
CVE-2021-33813P3HIGHCVSS 7.5v8.8.1v8.92021-06-16
CVE-2021-33813 [HIGH] CWE-611 CVE-2021-33813: An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
nvd
CVE-2023-50291P3HIGHCVSS 7.5≥ 6.0.0, < 8.11.3≥ 9.0.0, < 9.3.02024-02-09
CVE-2023-50291 [HIGH] CWE-522 CVE-2023-50291: Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr:
Insufficiently Protected Credentials vulnerability in Apache Solr.
This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0.
One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/properties, was only setup to hide system properties that had "password" contained in the name.
There are a n
nvd
CVE-2019-12401P3HIGHCVSS 7.5≥ 1.3.0, ≤ 1.4.1≥ 3.1, ≤ 3.6.2+4 more2019-09-10
CVE-2019-12401 [HIGH] CWE-776 CVE-2019-12401: Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource c
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.
nvd
CVE-2017-7660P3HIGHCVSS 7.5v5.3.0v5.3.1+19 more2017-07-07
CVE-2017-7660 [HIGH] CWE-287 CVE-2017-7660: Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled.
Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the nodes in cluster to believe that the malicious node is a member of the cluster. So, if Solr users have en
nvd
CVE-2023-50298P3HIGHCVSS 7.5≥ 6.0.0, < 8.11.3≥ 9.0.0, < 9.4.12024-02-09
CVE-2023-50298 [HIGH] CWE-200 CVE-2023-50298: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue a
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.
Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter.
When original SolrCloud is setup to use ZooKeeper credentials and ACLs,
nvd
CVE-2017-1000190P3CRITICALCVSS 9.1v8.4.12017-11-17
CVE-2017-1000190 [CRITICAL] CWE-611 CVE-2017-1000190: SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information d
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
nvd
CVE-2026-22444P3HIGHCVSS 7.1≥ 8.6.0, < 9.10.12026-01-21
CVE-2026-22444 [HIGH] CWE-20 CVE-2026-22444: The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some AP
The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security setting https://https://solr.apache.org/guide/solr/latest/configuration-guide/configuring-solr-xm
nvd
CVE-2017-9803P3HIGHCVSS 7.5v6.2.0v6.2.1+7 more2017-09-18
CVE-2017-9803 [HIGH] CWE-287 CVE-2017-9803: Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an applicatio
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be lea
nvd
CVE-2013-6408P3MEDIUMCVSS 6.4≤ 4.3.0v3.6.0+6 more2013-12-07
CVE-2013-6408 [MEDIUM] CVE-2013-6408: The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntity
The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an in
nvd
CVE-2013-6407P3MEDIUMCVSS 6.4≤ 4.0.0v3.6.0+3 more2013-12-07
CVE-2013-6407 [MEDIUM] CVE-2013-6407: The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspec
The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2018-8026P3MEDIUMCVSS 5.5≤ 6.6.4≥ 7.0.0, ≤ 7.3.12018-07-05
CVE-2018-8026 [MEDIUM] CWE-611 CVE-2018-8026: This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entit
This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can b
nvd
CVE-2018-8010P4MEDIUMCVSS 5.5≥ 6.0.0, ≤ 6.6.3≥ 7.0.0, ≤ 7.3.02018-05-21
CVE-2018-8010 [MEDIUM] CWE-611 CVE-2018-8010: This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity e
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in
nvd
CVE-2025-24814P4MEDIUMCVSS 5.5fixed in 9.8.02025-01-27
CVE-2025-24814 [MEDIUM] CWE-250 CVE-2025-24814: Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr i
Core creation allows users to replace "trusted" configset files with arbitrary configuration
Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization are vulnerable to a sort of privilege escalation wherein individual "tru
nvd