QID 730063

Date Published: 2021-04-28

QID 730063: Apache Solr SSRF vulnerability

Apache Solr is an open source enterprise search platform, written in Java, from the Apache Lucene project. Its major features include full-text search, hit highlighting, faceted search, real-time indexing, dynamic clustering, database integration, NoSQL features and rich document handling.

Affected Versions:
Apache Solr versions 8.0.0 to 8.8.1
Apache Solr versions 7.0.0 to 7.7.3

QID Detection Logic (Unauthenticated):
This QID sends a crafted HTTP request to check if the target is vulnerable or not.

Successful exploitation could lead to server side request forgery attack

  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Users are advised to upgrade to latest solr version Solr 8.8.2 or Apply the patch SOLR-15217

    CVEs related to QID 730063

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-27905 URL Logo solr.apache.org/security.html#cve-2021-27905-ssrf-vulnerability-with-the-replication-handler