VDB
Sign up
HIGH7.5

GHSA-ww97-9w65-2crx

Improper Input Validation in Apache Solr

Quick fix

GHSA-ww97-9w65-2crx — org.apache.solr:solr-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.4.0</version> for org.apache.solr:solr-core

Details

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.solr:solr-core
Introduced in: 5.0.0Fixed in: 8.4.0
Fix# pom.xml: bump <version>8.4.0</version> for org.apache.solr:solr-core
Maven/org.apache.solr:solr-core
Introduced in: 6.0.0Fixed in: 8.4.0
Fix# pom.xml: bump <version>8.4.0</version> for org.apache.solr:solr-core
Maven/org.apache.solr:solr-core
Introduced in: 7.0.0Fixed in: 8.4.0
Fix# pom.xml: bump <version>8.4.0</version> for org.apache.solr:solr-core
Maven/org.apache.solr:solr-core
Introduced in: 8.0.0Fixed in: 8.4.0
Fix# pom.xml: bump <version>8.4.0</version> for org.apache.solr:solr-core

References