VDB
Sign up
HIGH7.2

GHSA-3gm7-v7vw-866c

XML External Entity (XXE) Injection in Apache Solr

Quick fix

GHSA-3gm7-v7vw-866c — org.apache.solr:solr-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.2.0</version> for org.apache.solr:solr-core

Details

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.solr:solr-core
Introduced in: 0Fixed in: 8.2.0
Fix# pom.xml: bump <version>8.2.0</version> for org.apache.solr:solr-core

References