Описание
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
A flaw was found in the Apache Solr's Config API, where it would permit the configuration of the JMX server via an HTTP POST request. An attacker could use this flaw to direct traffic to a malicious RMI server, and then trigger remote code execution or conduct further attacks.
Меры по смягчению последствий
- Upgrade to 6.6.6 or later
- Disable the ConifgAPI if not in use (
disable.configEdit=true) - Use other external means to ensure only trusted traffic is allowed (block POST requests to the config API from external sources)
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Data Grid 6 | solr-core | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 6 | solr-core | Not affected | ||
| Red Hat JBoss Fuse 6 | solr-core | Affected | ||
| Red Hat JBoss Fuse Service Works 6 | solr-core | Out of support scope | ||
| Red Hat Fuse 7.4.0 | camel-solr | Fixed | RHSA-2019:2413 | 08.08.2019 |
Показывать по
Дополнительная информация
Статус:
9.8 Critical
CVSS3
Связанные уязвимости
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config ...
Critical severity vulnerability that affects org.apache.solr:solr-core
Уязвимость программного интерфейса Config поискового сервера Apache Solr, позволяющая нарушителю выполнить произвольный код
9.8 Critical
CVSS3