Apache Solr vulnerabilities
47 known vulnerabilities affecting apache/solr.
Total CVEs
47
CISA KEV
3
actively exploited
Public exploits
10
Exploited in wild
10
Severity breakdown
CRITICAL10HIGH21MEDIUM15LOW1
Vulnerabilities
Page 3 of 3
CVE-2015-8796P4MEDIUMCVSS 6.1≤ 5.2.12016-02-15
CVE-2015-8796 [MEDIUM] CWE-79 CVE-2015-8796: Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
nvd
CVE-2015-8797P4MEDIUMCVSS 6.1≤ 5.32016-02-15
CVE-2015-8797 [MEDIUM] CWE-79 CVE-2015-8797: Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in th
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
nvd
CVE-2015-8795P4MEDIUMCVSS 6.1≤ 5.02016-02-15
CVE-2015-8795 [MEDIUM] CWE-79 CVE-2015-8795: Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-
nvd
CVE-2018-11802P4MEDIUMCVSS 4.3≥ 4.2.0, < 6.6.6≥ 7.0.0, < 7.7.02020-04-01
CVE-2018-11802 [MEDIUM] CWE-863 CVE-2018-11802: In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all
nvd
CVE-2014-3628P4MEDIUMCVSS 4.3v4.0.0v4.1.0+19 more2015-01-06
CVE-2014-3628 [MEDIUM] CWE-79 CVE-2014-3628: Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x befo
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
nvd
CVE-2021-28163P4LOWCVSS 2.7v8.8.12021-04-01
CVE-2021-28163 [LOW] CWE-200 CVE-2021-28163: In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user use
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
nvd
CVE-2009-3821P4MEDIUMCVSS 4.3v1.0.02009-10-28
CVE-2009-3821 [MEDIUM] CWE-79 CVE-2009-3821: Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3
Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
← Previous3 / 3