Solr: Code execution via entity expansion
Published Oct 14, 2017
9.8
CRITICALCVSS 3.1
EPSS 91.90%
Description
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.
Affected products
- Vendor n/a Product Apache Solr before 7.1 with Apache Lucene before 7.1 Defaultn/a
- Version Apache Solr before 7.1 with Apache Lucene before 7.1StatusaffectedConstraints-
- Version lucene-solrStatusaffectedConstraints<5.3.1-redhat-2
- Version lucene-solrStatusaffectedConstraints<7.1.0
- Version lucene-solr 7.2.0StatusunaffectedConstraints-
- Version lucene-solr 8.0.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache Solr before 7.1 with Apache Lucene before 7.1 | n/a |
|
Configuration 1
Configuration 2
- 7.0.0
- 7.1.0
Running on/with
- 6.0
- 7.0
Configuration 3
- 7.0
- 8.0
- 9.0
Configuration 4
- 16.04
No data.
RHPAM 7.13.1 async
lucene
Fixed · RHSA-2023:1334
Red Hat JBoss Data Grid 7.1
n/a
Fixed · RHSA-2017:3244
Red Hat JBoss EAP 7
lucene-core
Fixed · RHSA-2018:0003
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-activemq-artemis-0:1.1.0-19.SP24_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-hibernate-0:5.0.16-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-ironjacamar-0:1.3.8-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el6
Fixed · RHSA-2018:0005
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-jboss-remoting-0:4.0.25-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-jboss-xnio-base-0:3.4.7-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-jgroups-0:3.6.12-1.Final_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-lucene-solr-0:5.3.1-4.redhat_2.1.ep7.el6
Fixed · RHSA-2017:3123
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-resteasy-0:3.0.19-7.SP5_redhat_1.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-undertow-0:1.3.31-3.Final_redhat_3.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-wildfly-0:7.0.9-4.GA_redhat_3.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
eap7-wildfly-javadocs-0:7.0.9-2.GA_redhat_3.1.ep7.el6
Fixed · RHSA-2018:0002
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-activemq-artemis-0:1.1.0-19.SP24_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-hibernate-0:5.0.16-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-ironjacamar-0:1.3.8-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el7
Fixed · RHSA-2018:0005
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-jboss-remoting-0:4.0.25-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-jboss-xnio-base-0:3.4.7-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-jgroups-0:3.6.12-1.Final_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-lucene-solr-0:5.3.1-4.redhat_2.1.ep7.el7
Fixed · RHSA-2017:3123
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-resteasy-0:3.0.19-7.SP5_redhat_1.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-undertow-0:1.3.31-3.Final_redhat_3.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-wildfly-0:7.0.9-4.GA_redhat_3.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
eap7-wildfly-javadocs-0:7.0.9-2.GA_redhat_3.1.ep7.el7
Fixed · RHSA-2018:0004
Red Hat JBoss Enterprise Application Platform 7.0 security update
n/a
Fixed · RHSA-2017:3124
Red Hat JBoss Enterprise Application Platform Continuous Delivery
lucene
Fixed · RHSA-2020:2561
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-java-common-lucene-0:4.8.0-6.9.el6
Fixed · RHSA-2017:3451
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-java-common-lucene5-0:5.4.1-2.4.el6
Fixed · RHSA-2017:3452
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-java-common-lucene-0:4.8.0-6.9.el6
Fixed · RHSA-2017:3451
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-java-common-lucene5-0:5.4.1-2.4.el6
Fixed · RHSA-2017:3452
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-java-common-lucene-0:4.8.0-6.9.el7
Fixed · RHSA-2017:3451
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-java-common-lucene5-0:5.4.1-2.4.el7
Fixed · RHSA-2017:3452
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-java-common-lucene-0:4.8.0-6.9.el7
Fixed · RHSA-2017:3451
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-java-common-lucene5-0:5.4.1-2.4.el7
Fixed · RHSA-2017:3452
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-java-common-lucene-0:4.8.0-6.9.el7
Fixed · RHSA-2017:3451
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-java-common-lucene5-0:5.4.1-2.4.el7
Fixed · RHSA-2017:3452
Red Hat BPM Suite 6
lucene
Not affected
Red Hat Enterprise Linux 5
lucene
Not affected
Red Hat Enterprise Linux 6
lucene
Will not fix
Red Hat Fuse 7
solr
Not affected
Red Hat JBoss BRMS 6
lucene
Not affected
Red Hat JBoss Data Grid 7
lucene
Affected
Red Hat JBoss Enterprise Application Platform 6
lucene
Not affected
Red Hat JBoss Enterprise Application Platform 6
solr
Not affected
Red Hat JBoss Fuse 6
camel
Not affected
Red Hat JBoss Portal 6
solr
Not affected
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-elasticsearch5
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-elasticsearch5
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-elasticsearch6
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-presto
Not affected
Red Hat Single Sign-On 7
lucene
Not affected
Red Hat Virtualization 4
lucene
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHPAM 7.13.1 async | lucene | Fixed | RHSA-2023:1334 |
| Red Hat JBoss Data Grid 7.1 | n/a | Fixed | RHSA-2017:3244 |
| Red Hat JBoss EAP 7 | lucene-core | Fixed | RHSA-2018:0003 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-activemq-artemis-0:1.1.0-19.SP24_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-hibernate-0:5.0.16-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-ironjacamar-0:1.3.8-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el6 | Fixed | RHSA-2018:0005 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-jboss-remoting-0:4.0.25-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-jboss-xnio-base-0:3.4.7-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-jgroups-0:3.6.12-1.Final_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-lucene-solr-0:5.3.1-4.redhat_2.1.ep7.el6 | Fixed | RHSA-2017:3123 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-resteasy-0:3.0.19-7.SP5_redhat_1.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-undertow-0:1.3.31-3.Final_redhat_3.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-wildfly-0:7.0.9-4.GA_redhat_3.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 | eap7-wildfly-javadocs-0:7.0.9-2.GA_redhat_3.1.ep7.el6 | Fixed | RHSA-2018:0002 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-activemq-artemis-0:1.1.0-19.SP24_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-hibernate-0:5.0.16-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-ironjacamar-0:1.3.8-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el7 | Fixed | RHSA-2018:0005 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-jboss-remoting-0:4.0.25-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-jboss-xnio-base-0:3.4.7-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-jgroups-0:3.6.12-1.Final_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-lucene-solr-0:5.3.1-4.redhat_2.1.ep7.el7 | Fixed | RHSA-2017:3123 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-resteasy-0:3.0.19-7.SP5_redhat_1.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-undertow-0:1.3.31-3.Final_redhat_3.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-wildfly-0:7.0.9-4.GA_redhat_3.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 | eap7-wildfly-javadocs-0:7.0.9-2.GA_redhat_3.1.ep7.el7 | Fixed | RHSA-2018:0004 |
| Red Hat JBoss Enterprise Application Platform 7.0 security update | n/a | Fixed | RHSA-2017:3124 |
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | lucene | Fixed | RHSA-2020:2561 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-java-common-lucene-0:4.8.0-6.9.el6 | Fixed | RHSA-2017:3451 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-java-common-lucene5-0:5.4.1-2.4.el6 | Fixed | RHSA-2017:3452 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-java-common-lucene-0:4.8.0-6.9.el6 | Fixed | RHSA-2017:3451 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-java-common-lucene5-0:5.4.1-2.4.el6 | Fixed | RHSA-2017:3452 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-java-common-lucene-0:4.8.0-6.9.el7 | Fixed | RHSA-2017:3451 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-java-common-lucene5-0:5.4.1-2.4.el7 | Fixed | RHSA-2017:3452 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-java-common-lucene-0:4.8.0-6.9.el7 | Fixed | RHSA-2017:3451 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-java-common-lucene5-0:5.4.1-2.4.el7 | Fixed | RHSA-2017:3452 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-java-common-lucene-0:4.8.0-6.9.el7 | Fixed | RHSA-2017:3451 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-java-common-lucene5-0:5.4.1-2.4.el7 | Fixed | RHSA-2017:3452 |
| Red Hat BPM Suite 6 | lucene | Not affected | n/a |
| Red Hat Enterprise Linux 5 | lucene | Not affected | n/a |
| Red Hat Enterprise Linux 6 | lucene | Will not fix | n/a |
| Red Hat Fuse 7 | solr | Not affected | n/a |
| Red Hat JBoss BRMS 6 | lucene | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | lucene | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | lucene | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | solr | Not affected | n/a |
| Red Hat JBoss Fuse 6 | camel | Not affected | n/a |
| Red Hat JBoss Portal 6 | solr | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-elasticsearch5 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-elasticsearch5 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-elasticsearch6 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-presto | Not affected | n/a |
| Red Hat Single Sign-On 7 | lucene | Not affected | n/a |
| Red Hat Virtualization 4 | lucene | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The following products are not affected by this flaw, as they do not use the vulnerable functionality of either aspect of the issue. Red Hat JBoss Enterprise Application Platform 6 Red Hat JBoss BPM Suite Red Hat JBoss BRMS Red Hat Enterprise Virtualization Manager Red Hat Single Sign-On 7 Red Hat JBoss Portal Platform 6 Red Hat JBoss Enterprise Application Platform 7 is not affected by this flaw. However, it does ship the vulnerable Lucene class in a dependency to another component. Customers who reuse the lucene-queryparser jar in their applications may be vulnerable to the External Entity Expansion aspect of this flaw. This will be patched in a forthcoming release. Red Hat JBoss Fuse is not affected by this flaw, as it does not use the vulnerable functionality of either aspect of this flaw. Fuse customers who may be running external Solr servers, while not affected from the Fuse side, are advised to secure their Solr servers as recommended in the mitigation provided. The following products ship only the Lucene components relevant to this flaw, and are not vulnerable to the second portion of the vulnerability, the code execution exploit. As such, the impact of this flaw has been determined to be Moderate for these respective products: Red Hat JBoss Data Grid 7 Red Hat Enterprise Linux 6 Red Hat Software Collections 2.4 This issue did not affect the versions of lucene as shipped with Red Hat Enterprise Linux 5. This issue does not affect Elasticsearch as shipped in OpenShift Container Platform.
Red Hat mitigation
Until fixes are available, all Solr users are advised to restart their Solr instances with the system parameter `-Ddisable.configEdit=true`. This will disallow any changes to be made to configurations via the Config API. This is a key factor in this vulnerability, since it allows GET requests to add the RunExecutableListener to the config. This is sufficient to protect from this type of attack, but means you cannot use the edit capabilities of the Config API until further fixes are in place.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 91.90% (0.91896) | 99.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 91.90% (0.91896) | 99.80th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.92% (0.93915) | 99.87th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.41% (0.97406) | 99.95th | v3 (v2023.03.01) |
| Jan 18, 2024 | 97.42% (0.97422) | 99.93th | v3 (v2023.03.01) |
| Oct 30, 2023 | 97.44% (0.97441) | 99.93th | v3 (v2023.03.01) |
| Sep 24, 2023 | 97.42% (0.97423) | 99.91th | v3 (v2023.03.01) |
| Aug 24, 2023 | 97.45% (0.97452) | 99.92th | v3 (v2023.03.01) |
| May 8, 2023 | 97.49% (0.97491) | 99.95th | v3 (v2023.03.01) |
| Mar 28, 2023 | 97.45% (0.97449) | 99.90th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.48% (0.97483) | 99.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 93.08% (0.93075) | 99.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 93.08% (0.93075) | 99.91th | v2 (v2022.01.01) |
| Feb 3, 2022 | 61.42% (0.61417) | 99.31th | v1 |
| Sep 1, 2021 | 61.42% (0.61417) | 99.79th | v1 |
| Aug 18, 2021 | 61.42% (0.61417) | 0.00th | v1 |
| Jul 29, 2021 | 60.44% (0.60438) | 0.00th | v1 |
| Jun 19, 2021 | 59.41% (0.59408) | 0.00th | v1 |
| Apr 14, 2021 | 57.18% (0.57181) | 0.00th | v1 |
References (38)
- http://mail-archives.us.apache.org/mod_mbox/www-announce/201710.mbox/%3CCAOOKt51UO_6Vy%3Dj8W%3Dx1pMbLW9VJfZyFWz7pAnXJC_OAdSZubA%40mail.gmail.com%3E mailing-listx_refsource_MLISTMailing ListVendor Advisory
- http://openwall.com/lists/oss-security/2017/10/13/1 x_refsource_MISCMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/101261 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:3123 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3124 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3244 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3451 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3452 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0002 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0003 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0004 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0005 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-12629 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/CVE-2017-12629
- https://bugzilla.redhat.com/show_bug.cgi?id=1501529 Issue Tracking
- https://github.com/advisories/GHSA-mh7g-99w9-xpjm Advisory
- https://github.com/apache/lucene-solr/commit/3bba91131b5257e64b9d0a2193e1e32a145b2a2
- https://github.com/apache/lucene-solr/commit/d8000beebfb13ba0b6e754f84c760e11592d8d1
- https://github.com/apache/lucene-solr/commit/f9fd6e9e26224f26f1542224ce187e04c27b268
- https://issues.apache.org/jira/browse/SOLR-11477
- https://lists.apache.org/thread.html/r140128dc6bb4f4e0b6a39e962c7ca25a8cbc8e48ed766176c931fccc%40%3Cusers.solr.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r140128dc6bb4f4e0b6a39e962c7ca25a8cbc8e48ed766176c931fccc@%3Cusers.solr.apache.org%3E
- https://lists.apache.org/thread.html/r26c996b068ef6c5e89aa59acb769025cfd343a08e63fbe9e7f3f720f%40%3Coak-issues.jackrabbit.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r26c996b068ef6c5e89aa59acb769025cfd343a08e63fbe9e7f3f720f@%3Coak-issues.jackrabbit.apache.org%3E
- https://lists.apache.org/thread.html/r3da74965aba2b5f5744b7289ad447306eeb2940c872801819faa9314%40%3Cusers.solr.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3da74965aba2b5f5744b7289ad447306eeb2940c872801819faa9314@%3Cusers.solr.apache.org%3E
- https://lists.apache.org/thread.html/r95df34bb158375948da82b4dfe9a1b5d528572d586584162f8f5aeef%40%3Cusers.solr.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r95df34bb158375948da82b4dfe9a1b5d528572d586584162f8f5aeef@%3Cusers.solr.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/01/msg00028.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-12629
- https://s.apache.org/FJDl mailing-listx_refsource_MLISTExploitMailing ListVendor Advisory
- https://twitter.com/ApacheSolr/status/918731485611401216 x_refsource_MISCThird Party Advisory
- https://twitter.com/joshbressers/status/919258716297420802 x_refsource_MISCThird Party Advisory
- https://twitter.com/searchtools_avi/status/918904813613543424 x_refsource_MISCThird Party Advisory
- https://usn.ubuntu.com/4259-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-12629
- https://www.debian.org/security/2018/dsa-4124 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.exploit-db.com/exploits/43009 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.