Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrh8-27q8-fr8f

Опубликовано: 14 мар. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

Пакеты

Наименование

org.apache.solr:solr-core

maven
Затронутые версииВерсия исправления

>= 1.30, <= 7.6.0

7.7.0

EPSS

Процентиль: 98%
0.55454
Средний

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

CVSS3: 7.5
nvd
почти 7 лет назад

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

CVSS3: 7.5
debian
почти 7 лет назад

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (in ...

EPSS

Процентиль: 98%
0.55454
Средний

7.5 High

CVSS3

Дефекты

CWE-918