Junglewise Threat Intelligence

CVE-2019-0193: XML External Entity (XXE) Injection in Apache Solr

CVE-2019-0193 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2019-08-01

Technologies: Apache Solr. Vendors: Apache, Maven.

Executive brief

The Apache Solr DataImportHandler (DIH) module contains a code injection vulnerability via the 'dataConfig' parameter. An attacker can exploit this by providing a malicious configuration containing scripts, which are executed during the DIH debug mode. Starting with version 8.2.0, this parameter is disabled by default.

Affected products

  • Apache Solr prior to 8.2.0

Timeline

  • 2021-12-10: disclosed
  • 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-10: other: CISA KEV remediation due date

Related threats