Search CVE reports


Toggle filters

11 – 20 of 38 results


CVE-2023-50290

Medium priority
Needs evaluation

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-26336

Low priority
Needs evaluation

A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application...

2 affected packages

libapache-poi-java, lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-poi-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lucene-solr Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-29943

Medium priority
Vulnerable

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-29262

Medium priority
Vulnerable

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-27905

Medium priority
Needs evaluation

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-13957

Medium priority
Not affected

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Not affected Not affected
Show less packages

CVE-2020-13941

Medium priority
Needs evaluation

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-11802

Medium priority
Needs evaluation

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-17558

High priority
Ignored

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Not affected Not affected Not affected Not affected
Show less packages

CVE-2019-12409

Medium priority
Not affected

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file...

1 affected package

lucene-solr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lucene-solr Not affected
Show less packages