Server-side request forgery (SSRF) In org.apache.solr:solr-core
Description
Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 7.7.0 | ||
debian 14 | - | ||
debian 13 | - | ||
debian 12 | - | ||
debian 11 | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.