MEDIUM
Solr: directory traversal when loading XSL stylesheets and Velocity templates
Published Dec 7, 2013
4.3
MEDIUMCVSS 2.0
EPSS 56.26%
Description
Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries.
Affected products
No data.
OR
- ≤ 4.5.1
- 4.0.0
- 4.0.0
- 4.0.0
- 4.1.0
- 4.2.0
- 4.2.1
- 4.3.0
- 4.3.1
- 4.4.0
- 4.5.0
No data.
Red Hat JBoss Data Grid 6.2
n/a
Fixed · RHSA-2014:0029
Red Hat JBoss Web Framework Kit 2.4
n/a
Fixed · RHSA-2013:1844
Red Hat JBoss Data Grid 6
solr
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Grid 6.2 | n/a | Fixed | RHSA-2014:0029 |
| Red Hat JBoss Web Framework Kit 2.4 | n/a | Fixed | RHSA-2013:1844 |
| Red Hat JBoss Data Grid 6 | solr | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (17)
- http://lucene.apache.org/solr/4_6_0/changes/Changes.html x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2013-1844.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0029.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/55730 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/59372 third-party-advisoryx_refsource_SECUNIA
- http://www.agarri.fr/kom/archives/2013/11/27/compromising_an_unreachable_solr_server_with_cve-2013-6397/index.html x_refsource_MISCExploit
- http://www.openwall.com/lists/oss-security/2013/11/27/1 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/63935 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-6397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1035062 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4317 Advisory
- https://github.com/advisories/GHSA-j8qw-mwmv-28cg Advisory
- https://github.com/apache/lucene-solr/commit/da34b18cb3092df4972e2b6fa5178d1059923910
- https://issues.apache.org/jira/browse/SOLR-4882 x_refsource_CONFIRMPatch
- https://nvd.nist.gov/vuln/detail/CVE-2013-6397
- https://web.archive.org/web/20170307173358/http://www.securityfocus.com/bid/63935
- https://www.cve.org/CVERecord?id=CVE-2013-6397
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 7, 2013
Updated Aug 6, 2024
Reserved Nov 4, 2013
Link CVE-2013-6397
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4317 GHSA-J8QW-MWMV-28CG Assigner redhat
Published Dec 7, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2022-4317