| Reference | Source | Link | Tags |
|---|
| Apache Solr 7.0.1 - XML External Entity Expansion / Remote Code Execution |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| Apache Solr na Twitterze: "Please secure your #Solr servers since a zero-day exploit has been reported on a public mailing list -- see https://t.co/mFDvxrdm0T" |
MISC |
twitter.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Josh Bressers na Twitterze: "I've had a number of people ask me about CVE-2017-12629. The lucene XXE issue doesn't affect Elasticsearch.
https://t.co/9F1wsrtt6Q" |
MISC |
twitter.com |
Third Party Advisory |
| [ANNOUNCE] [SECURITY] CVE-2017-12629: Several critical vulnerabilities discovered in Apache Solr (XXE & RCE) |
MLIST |
mail-archives.us.apache.org |
Mailing List, Vendor Advisory |
| [solr-users] 20210618 CVE-2021-27905 Apache Solr ReplicationHandler/SSRF vulnerability |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| oss-security - CVE-2017-12629 Solr: Code execution via entity expansion |
MISC |
openwall.com |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [SECURITY] [DLA 1254-1] lucene-solr security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| USN-4259-1: Apache Solr vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [solr-users] 20210618 Re: CVE-2021-27905 Apache Solr ReplicationHandler/SSRF vulnerability |
|
lists.apache.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [jackrabbit-oak-issues] 20210817 [jira] [Created] (OAK-9537) Security vulnerability in org/apache/lucene/queryparser/xml/CoreParser.java |
|
lists.apache.org |
|
| Re: Several critical vulnerabilities discovered in Apache Solr (XXE & RCE) |
MLIST |
s.apache.org |
Exploit, Mailing List, Vendor Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [solr-users] 20210728 Re: CVE-2021-27905 Apache Solr ReplicationHandler/SSRF vulnerability |
|
lists.apache.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| SearchTools_Avi na Twitterze: "Lucidworks Fusion does not use the Solr’s Config API, to avoid the vulnerability, add the startup flag -Ddisable.configEdit=true" |
MISC |
twitter.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4124-1 lucene-solr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |