Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12401

Опубликовано: 09 сент. 2019
Источник: redhat
CVSS3: 7.5

Описание

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Virtualization 6solr-coreOut of support scope
Red Hat JBoss Enterprise Application Platform 6solr-coreOut of support scope
Red Hat JBoss Fuse 6solr-coreNot affected
Red Hat JBoss Fuse Service Works 6solr-coreNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1789513solr: XML resource consumption attack via update handler

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

CVSS3: 7.5
debian
больше 6 лет назад

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are v ...

CVSS3: 7.5
github
больше 3 лет назад

Apache Solr vulnerable to XML Bomb

7.5 High

CVSS3