XML injection (XXE) In org.apache.solr:solr-core
Description
There is a XML external entity expansion (XXE) vulnerability in Apache Solr
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the &dataConfig=<inlinexml> parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 6.6.3, 7.3.0 | ||
debian 13 | 3.6.2+dfsg-12 | ||
debian 12 | 3.6.2+dfsg-12 | ||
debian 14 | 3.6.2+dfsg-12 | ||
debian 11 | 3.6.2+dfsg-12 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7.