QID 730804

Date Published: 2023-05-25

QID 730804: Apache Solr Denial of Service (DoS) Vulnerability

Apache Calcite has a vulnerability, CVE-2022-39135, that is exploitable in Apache Solr in SolrCloud mode. If an untrusted user can supply SQL queries to Solrs sql handler even indirectly via proxies other apps, then the user could perform an XML External Entity XXE attack. This might have been exposed by some deployers of Solr in order for internal analysts to use JDBC based tooling, but would have unlikely been granted to wider audiences.

Affected Versions:
Apache Solr 6.5 to 8.11.2
Apache Solr 9.0
QID Detection Logic:
This QID sends a HTTP GET request to "solr/admin/info/system" endpoint and check for Apache Solr Version.

Note: This issue has Mitigation, hence the detection is kept as potential.

An XXE attack may lead to the disclosure of confidential data, denial of service, server side request forgery (SSRF), port scanning from the Solr node, and other system impacts.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to Apache Solr 9.2.1 or later version to remediate this vulnerability. For more information please refer to Apache Solr Security advisory

    CVEs related to QID 730804

    Software Advisories
    Advisory ID Software Component Link
    Apache Solr advisory URL Logo solr.apache.org/security.html#apache-solr-is-vulnerable-to-cve-2022-39135-via-sql-handler