Executive brief
Apache Solr is vulnerable to Remote Code Execution via the VelocityResponseWriter plug-in. An attacker can trigger execution by providing malicious Velocity templates through a configset directory or by enabling the 'params.resource.loader.enabled' setting via the Configuration API.
Affected products
- Apache Solr 5.0.0 to 8.3.1
Timeline
- 2021-11-03: disclosed
- exploited: Reported exploited in the wild.