QID 981344
QID 981344: Java (maven) Security Update for org.apache.solr:solr-core (GHSA-3pph-2595-cgfh)
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3pph-2595-cgfh for updates pertaining to this vulnerability.
Vendor References
- GHSA-3pph-2595-cgfh -
github.com/advisories/GHSA-3pph-2595-cgfh
CVEs related to QID 981344
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3pph-2595-cgfh | org.apache.solr:solr-core |
|