Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2019-0192

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure…

Technology

Apache Solr

CVSS Score

9.8 / 10.0

Affected Versions

>=5.0.0 <=5.5.5; >=6.0.0 <=6.6.5

Upstream Fix

See upstream advisory

Published

March 7, 2019

OSSeva Coverage

Fixed upstream

Description

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

Is your Apache Solr deployment affected?

If you're running >=5.0.0 <=5.5.5; >=6.0.0 <=6.6.5, you need this patch. Book a discovery call to get covered.