QID 731152
Date Published: 2024-02-19
QID 731152: Apache Solr Remote Code Execution (RCE) Vulnerability
Solr is highly reliable, scalable and fault tolerant, providing distributed indexing, replication and load-balanced querying, automated failover and recovery, centralized configuration and more. Solr powers the search and navigation features of many of the world's largest internet sites
CVE-2023-50292 : Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
Affected Versions:
Solr 6.0.0 to 8.11.2
Solr 9.0.0 before 9.3.0
QID Detection Logic:
This QID sends a HTTP GET request to "solr/admin/info/system" endpoint and check for Apache Solr Version.
Successful exploitation of this vulnerability causes non-authenticated users are unable to perform Remote Code Execution
CVEs related to QID 731152
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Solr advisory |
|