CVE-2017-12629

Summary

CVECVE-2017-12629
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2017-10-14 23:29:00 UTC
Updated2023-11-07 02:38:00 UTC
DescriptionRemote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

Risk And Classification

Problem Types: CWE-611

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Apache Solr All All All All
Application Apache Solr All All All All
Application Apache Solr All All All All
Operating System Canonical Ubuntu Linux 16.04 All All All
Operating System Canonical Ubuntu Linux 16.04 All All All
Operating System Debian Debian Linux 7.0 All All All
Operating System Debian Debian Linux 8.0 All All All
Operating System Debian Debian Linux 9.0 All All All
Operating System Debian Debian Linux 7.0 All All All
Operating System Debian Debian Linux 8.0 All All All
Operating System Debian Debian Linux 9.0 All All All
Operating System Redhat Enterprise Linux Server 6.0 All All All
Operating System Redhat Enterprise Linux Server 7.0 All All All
Operating System Redhat Enterprise Linux Server 6.0 All All All
Operating System Redhat Enterprise Linux Server 7.0 All All All
Application Redhat Jboss Enterprise Application Platform 7.0.0 All All All
Application Redhat Jboss Enterprise Application Platform 7.1.0 All All All
Application Redhat Jboss Enterprise Application Platform 7.0.0 All All All
Application Redhat Jboss Enterprise Application Platform 7.1.0 All All All

References

ReferenceSourceLinkTags
Apache Solr 7.0.1 - XML External Entity Expansion / Remote Code Execution EXPLOIT-DB www.exploit-db.com Exploit, Third Party Advisory, VDB Entry
Apache Solr na Twitterze: "Please secure your #Solr servers since a zero-day exploit has been reported on a public mailing list -- see https://t.co/mFDvxrdm0T" MISC twitter.com Third Party Advisory
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
Pony Mail! MLIST lists.apache.org
Josh Bressers na Twitterze: "I've had a number of people ask me about CVE-2017-12629. The lucene XXE issue doesn't affect Elasticsearch. https://t.co/9F1wsrtt6Q" MISC twitter.com Third Party Advisory
[ANNOUNCE] [SECURITY] CVE-2017-12629: Several critical vulnerabilities discovered in Apache Solr (XXE & RCE) MLIST mail-archives.us.apache.org Mailing List, Vendor Advisory
[solr-users] 20210618 CVE-2021-27905 Apache Solr ReplicationHandler/SSRF vulnerability lists.apache.org
Pony Mail! MLIST lists.apache.org
oss-security - CVE-2017-12629 Solr: Code execution via entity expansion MISC openwall.com Mailing List, Third Party Advisory
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
[SECURITY] [DLA 1254-1] lucene-solr security update MLIST lists.debian.org Mailing List, Third Party Advisory
USN-4259-1: Apache Solr vulnerability | Ubuntu security notices | Ubuntu UBUNTU usn.ubuntu.com Third Party Advisory
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
[solr-users] 20210618 Re: CVE-2021-27905 Apache Solr ReplicationHandler/SSRF vulnerability lists.apache.org
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
Apache Solr/Lucene CVE-2017-12629 Information Disclosure and Remote Code Execution Vulnerabilities BID www.securityfocus.com Third Party Advisory, VDB Entry
[jackrabbit-oak-issues] 20210817 [jira] [Created] (OAK-9537) Security vulnerability in org/apache/lucene/queryparser/xml/CoreParser.java lists.apache.org
Re: Several critical vulnerabilities discovered in Apache Solr (XXE & RCE) MLIST s.apache.org Exploit, Mailing List, Vendor Advisory
Pony Mail! MLIST lists.apache.org
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
[solr-users] 20210728 Re: CVE-2021-27905 Apache Solr ReplicationHandler/SSRF vulnerability lists.apache.org
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
SearchTools_Avi na Twitterze: "Lucidworks Fusion does not use the Solr’s Config API, to avoid the vulnerability, add the startup flag -Ddisable.configEdit=true" MISC twitter.com Third Party Advisory
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
Debian -- Security Information -- DSA-4124-1 lucene-solr DEBIAN www.debian.org Third Party Advisory
Red Hat Customer Portal REDHAT access.redhat.com Third Party Advisory
Pony Mail! MLIST lists.apache.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 981499 Java (maven) Security Update for org.apache.solr:solr-core (GHSA-mh7g-99w9-xpjm)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report