Back

HIGH

Solr: XML external entity expansion in handler/dataimport/DataImporter.java allows remote attackers to read arbitrary files

Published Apr 9, 2018

Description

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 9, 2018
Updated Sep 17, 2024
Reserved Dec 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 12, 2018
GHSA-3PPH-2595-CGFH