Known Vulnerabilities for Solr by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Solr" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-44487 json | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many stre... | 7.5 - HIGH | 2023-10-10 | 2024-02-02 |
| CVE-2021-44548 json | An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC pa... | 9.8 - CRITICAL | 2021-12-23 | 2022-08-09 |
| CVE-2021-33813 json | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | 7.5 - HIGH | 2021-06-16 | 2023-11-07 |
| CVE-2021-29943 json | When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy ... | 9.1 - CRITICAL | 2021-04-13 | 2021-06-08 |
| CVE-2021-29262 json | When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACL... | 7.5 - HIGH | 2021-04-13 | 2023-11-07 |
| CVE-2021-28164 json | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e... | 5.3 - MEDIUM | 2021-04-01 | 2023-11-07 |
| CVE-2021-28163 json | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory tha... | 2.7 - LOW | 2021-04-01 | 2023-11-07 |
| CVE-2021-27905 json | The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "lead... | 9.8 - CRITICAL | 2021-04-13 | 2023-11-07 |
| CVE-2020-28052 json | An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method ... | 8.1 - HIGH | 2020-12-18 | 2023-11-07 |
| CVE-2020-27223 json | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing ... | 5.3 - MEDIUM | 2021-02-26 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Solr | 8.6.3 | |||
| Application | Apache | Solr | 8.6.2 | |||
| Application | Apache | Solr | 8.6.1 | |||
| Application | Apache | Solr | 8.6.0 | |||
| Application | Apache | Solr | 8.5.2 | |||
| Application | Apache | Solr | 8.5.1 | |||
| Application | Apache | Solr | 8.5.0 | |||
| Application | Apache | Solr | 8.4.1 | |||
| Application | Apache | Solr | 8.4.0 | |||
| Application | Apache | Solr | 8.3.1 | |||
| Application | Apache | Solr | 8.3.0 | |||
| Application | Apache | Solr | 8.2.0 | |||
| Application | Apache | Solr | 8.1.1 | |||
| Application | Apache | Solr | 8.1.0 | |||
| Application | Apache | Solr | 8.0.0 | |||
| Application | Apache | Solr | 7.7.3 | |||
| Application | Apache | Solr | 7.7.2 | |||
| Application | Apache | Solr | 7.7.1 | |||
| Application | Apache | Solr | 7.7.0 | |||
| Application | Apache | Solr | 7.6.0 |