Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-3164

Опубликовано: 08 мар. 2019
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 5
CVSS3: 7.5

Описание

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

needed

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/xenial

needed

Показывать по

EPSS

Процентиль: 98%
0.55454
Средний

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 7 лет назад

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.

CVSS3: 7.5
debian
почти 7 лет назад

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (in ...

CVSS3: 7.5
github
почти 7 лет назад

Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core

EPSS

Процентиль: 98%
0.55454
Средний

5 Medium

CVSS2

7.5 High

CVSS3