Логотип exploitDog
bind:CVE-2019-12401
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-12401

Количество 4

Количество 4

redhat логотип

CVE-2019-12401

больше 6 лет назад

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2019-12401

больше 6 лет назад

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2019-12401

больше 6 лет назад

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are v ...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-jq2w-w7v2-69q5

больше 3 лет назад

Apache Solr vulnerable to XML Bomb

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-12401

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

CVSS3: 7.5
28%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-12401

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

CVSS3: 7.5
28%
Средний
больше 6 лет назад
debian логотип
CVE-2019-12401

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are v ...

CVSS3: 7.5
28%
Средний
больше 6 лет назад
github логотип
GHSA-jq2w-w7v2-69q5

Apache Solr vulnerable to XML Bomb

CVSS3: 7.5
28%
Средний
больше 3 лет назад

Уязвимостей на страницу