CVE-2018-1308
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 21.19% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- apache/solr · debian/debian linux
- Source
- security@apache.org
References
- https://issues.apache.org/jira/browse/SOLR-11971Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/04/msg00025.htmlThird Party Advisory
- https://mail-archives.apache.org/mod_mbox/www-announce/201804.mbox/%3C000001d3cf68%245ac69af0%241053d0d0%24%40apache.org%3EMitigation, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4194Third Party Advisory
- https://issues.apache.org/jira/browse/SOLR-11971Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/04/msg00025.htmlThird Party Advisory
- https://mail-archives.apache.org/mod_mbox/www-announce/201804.mbox/%3C000001d3cf68%245ac69af0%241053d0d0%24%40apache.org%3EMitigation, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4194Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.