Lack of data validation In lucene-solr
Description
XML External Entity (XXE) Injection in Apache Solr In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 3.6.2+dfsg-22 | ||
debian 13 | 3.6.2+dfsg-22 | ||
maven | 8.2.0 | ||
debian 11 | 3.6.2+dfsg-22 | ||
debian 12 | 3.6.2+dfsg-22 |
Aliases
References