VendorsApachesolrany version
Vulnerabilities

Apache Solr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2021-27905
SSRF vulnerability with the Replication handler
Published 2021-04-13 · Modified
9.8EPSS 0.931
CVE-2017-12629
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.
Published 2017-10-14 · Modified
9.81 PoCEPSS 0.919
CVE-2024-45216
Apache Solr: Authentication bypass possible using a fake URL Path ending
Published 2024-10-16 · Analyzed
9.8EPSS 0.917
CVE-2020-13957
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.
Published 2020-10-13 · Modified
9.8EPSS 0.793
CVE-2019-0192
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
Published 2019-03-07 · Modified
9.8EPSS 0.775
CVE-2021-44548
Apache Solr information disclosure vulnerability through DataImportHandler
Published 2021-12-23 · Modified
9.8EPSS 0.051
CVE-2026-44825
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
Published 2026-06-01 · Analyzed
9.8EPSS 0.029
CVE-2021-29943
Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections
Published 2021-04-13 · Modified
9.1EPSS 0.047
CVE-2019-0193
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
Published 2019-08-01 · Analyzed
9.0KEVEPSS 0.835
CVE-2023-50386
Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
Published 2024-02-09 · Modified
8.8EPSS 0.837
CVE-2020-13941
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e you could read/write to any location the solr user can access.
Published 2020-08-17 · Modified
8.8EPSS 0.039
CVE-2026-22022
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
Published 2026-01-21 · Analyzed
8.2EPSS 0.006
CVE-2024-45217
Apache Solr: ConfigSets created during a backup restore command are trusted implicitly
Published 2024-10-16 · Analyzed
8.1EPSS 0.007
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2019-17558
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
Published 2019-12-30 · Analyzed
7.5KEV2 PoCEPSS 0.986
CVE-2018-1308
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
Published 2018-04-09 · Modified
7.5EPSS 0.208
CVE-2017-3164
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
Published 2019-03-08 · Modified
7.5EPSS 0.194
CVE-2012-6612
The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.
Published 2013-12-07 · Modified
7.5EPSS 0.101
CVE-2019-12401
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.
Published 2019-09-10 · Modified
7.5EPSS 0.085
CVE-2021-29262
Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings
Published 2021-04-13 · Modified
7.5EPSS 0.067
CVE-2017-3163
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.
Published 2017-08-30 · Modified
7.5EPSS 0.066
CVE-2023-50291
Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords
Published 2024-02-09 · Modified
7.5EPSS 0.033
CVE-2023-50292
Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users
Published 2024-02-09 · Modified
7.5EPSS 0.030
CVE-2023-50298
Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions
Published 2024-02-09 · Modified
7.5EPSS 0.016
CVE-2026-22444
Apache Solr: Insufficient file-access checking in standalone core-creation requests
Published 2026-01-21 · Analyzed
7.1EPSS 0.007
CVE-2023-50290
Apache Solr: Host environment variables are published via the Metrics API
Published 2024-01-15 · Modified
6.5EPSS 0.684
CVE-2013-6408
The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407.
Published 2013-12-07 · Modified
6.4EPSS 0.114
CVE-2013-6407
The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Published 2013-12-07 · Modified
6.4EPSS 0.114
CVE-2015-8796
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
Published 2016-02-15 · Modified
6.1EPSS 0.033
CVE-2015-8797
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
Published 2016-02-15 · Modified
6.1EPSS 0.033
CVE-2015-8795
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.
Published 2016-02-15 · Modified
6.1EPSS 0.027
CVE-2018-8026
This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. The manipulated files can be uploaded as configsets using Solr's API, allowing to exploit that vulnerability.
Published 2018-07-05 · Modified
5.5EPSS 0.090
CVE-2018-8010
This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resources below the Solr instance directory (using Solr's ResourceLoader); usage of absolute URLs is denied. Keep in mind, that external entities and XInclude are explicitly supported to better structure config files in large installations. Before Solr 6 this was no problem, as config files were not accessible through the APIs.
Published 2018-05-21 · Modified
5.5EPSS 0.039
CVE-2025-24814
Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files
Published 2025-01-27 · Analyzed
5.5EPSS 0.012
CVE-2024-52012
Apache Solr: Configset upload on Windows allows arbitrary path write-access
Published 2025-01-27 · Analyzed
5.4EPSS 0.450
CVE-2013-6397
Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries.
Published 2013-12-07 · Modified
4.3EPSS 0.563
CVE-2018-11802
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for such requests. This affects all Solr versions prior to 7.7 that use the default authorization mechanism of Solr (RuleBasedAuthorizationPlugin).
Published 2020-04-01 · Analyzed
4.3EPSS 0.020