Back to Vulnerability Directory
HIGHFixed upstream
CVE-2019-17558
Apache Solr: remote code execution through the VelocityResponseWriter
Technology
Apache Solr
CVSS Score
7.5 / 10.0
Affected Versions
5.0.0 to 8.3.1
Upstream Fix
8.4.0
Published
December 30, 2019
OSSeva Coverage
Fixed upstream
Description
A Velocity template supplied through a configset's velocity directory or as a request parameter can execute code on the Solr server. Parameter templates are off by default but can be switched on by anyone with access to the config API. Solr 8.4 removed the params resource loader and renders configset templates only when the configset is trusted. Rated high by the Solr PMC.
Is your Apache Solr deployment affected?
If you're running 5.0.0 to 8.3.1, you need this patch. Book a discovery call to get covered.