Apache Software Foundation Apache Solr vulnerabilities
24 known vulnerabilities affecting apache_software_foundation/apache_solr.
Total CVEs
24
CISA KEV
0
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL6HIGH13MEDIUM5
Vulnerabilities
Page 2 of 2
CVE-2017-9803P3HIGHCVSS 7.5v6.2.0 to 6.6.02017-09-18
CVE-2017-9803 [HIGH] CWE-287 CVE-2017-9803: Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an applicatio
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to the security configuration can be lea
nvd
CVE-2018-8026P3MEDIUMCVSS 5.5v6.0.0 to 6.6.4v7.0.0 to 7.3.12018-07-05
CVE-2018-8026 [MEDIUM] CWE-611 CVE-2018-8026: This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entit
This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can b
nvd
CVE-2018-8010P4MEDIUMCVSS 5.5vApache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.02018-05-21
CVE-2018-8010 [MEDIUM] CWE-611 CVE-2018-8010: This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity e
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in
nvd
CVE-2025-24814P4MEDIUMCVSS 5.5≤ 9.72025-01-27
CVE-2025-24814 [MEDIUM] CWE-250 CVE-2025-24814: Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr i
Core creation allows users to replace "trusted" configset files with arbitrary configuration
Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization are vulnerable to a sort of privilege escalation wherein individual "tru
nvd
← Previous2 / 2