This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1360-1 lucene-solr security update
Debian DSA Debian DSA DSA-4194-1 lucene-solr security update
EUVD EUVD EUVD-2018-0489 This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
Github GHSA Github GHSA GHSA-3pph-2595-cgfh There is a XML external entity expansion (XXE) vulnerability in Apache Solr
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-17T02:47:11.497Z

Reserved: 2017-12-07T00:00:00

Link: CVE-2018-1308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-09T13:29:00.820

Modified: 2024-11-21T03:59:35.683

Link: CVE-2018-1308

cve-icon Redhat

Severity : Important

Publid Date: 2018-02-12T00:00:00Z

Links: CVE-2018-1308 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses