Back to Vulnerability Directory
HIGHFixed upstream

CVE-2019-17558

Apache Solr: remote code execution through the VelocityResponseWriter

Technology

Apache Solr

CVSS Score

7.5 / 10.0

Affected Versions

5.0.0 to 8.3.1

Upstream Fix

8.4.0

Published

December 30, 2019

OSSeva Coverage

Fixed upstream

Description

A Velocity template supplied through a configset's velocity directory or as a request parameter can execute code on the Solr server. Parameter templates are off by default but can be switched on by anyone with access to the config API. Solr 8.4 removed the params resource loader and renders configset templates only when the configset is trusted. Rated high by the Solr PMC.

Upstream record: NVD · CVE.org

Is your Apache Solr deployment affected?

If you're running 5.0.0 to 8.3.1, you need this patch. Book a discovery call to get covered.