QID 730063
Date Published: 2021-04-28
QID 730063: Apache Solr SSRF vulnerability
Apache Solr is an open source enterprise search platform, written in Java, from the Apache Lucene project. Its major features include full-text search, hit highlighting, faceted search, real-time indexing, dynamic clustering, database integration, NoSQL features and rich document handling.
Affected Versions:
Apache Solr versions 8.0.0 to 8.8.1
Apache Solr versions 7.0.0 to 7.7.3
QID Detection Logic (Unauthenticated):
This QID sends a crafted HTTP request to check if the target is vulnerable or not.
Successful exploitation could lead to server side request forgery attack
Solution
Users are advised to upgrade to latest solr version Solr 8.8.2 or Apply the patch SOLR-15217
Vendor References
CVEs related to QID 730063
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-27905 |
|