cbcvebase.

Apache Software Foundation Apache Solr vulnerabilities

24 known vulnerabilities affecting apache_software_foundation/apache_solr.

Total CVEs
24
CISA KEV
0
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL6HIGH13MEDIUM5

Vulnerabilities

Page 2 of 2
CVE-2017-9803P3HIGHCVSS 7.5v6.2.0 to 6.6.02017-09-18
CVE-2017-9803 [HIGH] CWE-287 CVE-2017-9803: Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an applicatio Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be lea
nvd
CVE-2018-8026P3MEDIUMCVSS 5.5v6.0.0 to 6.6.4v7.0.0 to 7.3.12018-07-05
CVE-2018-8026 [MEDIUM] CWE-611 CVE-2018-8026: This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entit This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can b
nvd
CVE-2018-8010P4MEDIUMCVSS 5.5vApache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.02018-05-21
CVE-2018-8010 [MEDIUM] CWE-611 CVE-2018-8010: This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity e This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in
nvd
CVE-2025-24814P4MEDIUMCVSS 5.5≤ 9.72025-01-27
CVE-2025-24814 [MEDIUM] CWE-250 CVE-2025-24814: Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr i Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization are vulnerable to a sort of privilege escalation wherein individual "tru
nvd
Apache Software Foundation Apache Solr vulnerabilities | cvebase