Back

MEDIUM

Solr: directory traversal when loading XSL stylesheets and Velocity templates

Published Dec 7, 2013

Description

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 7, 2013
Updated Aug 6, 2024
Reserved Nov 4, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 26, 2013
ENISA EUVD
Assigner redhat
Published Dec 7, 2013
Updated Aug 6, 2024
Exploited since n/a
EUVD-2022-4317 GHSA-J8QW-MWMV-28CG