Back

HIGH KEV

solr: Remote Code Execution via DataImportHandler

Published Aug 1, 2019 ·Due Jun 10, 2022

Description

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.

Affected products

Remediation

Red Hat mitigation

Edit solrconfig.xml to configure all DataImportHandler usages with an "invariants" section listing the "dataConfig" parameter set to am empty string, or ensure your network settings are configured so that only trusted traffic communicates with Solr, especially to the DataImportHandler (although this is a best practice regardless) (ref: https://issues.apache.org/jira/browse/SOLR-13669)

Metrics

References (50)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 1, 2019
Updated Oct 21, 2025
Reserved Nov 14, 2018
CISA Vulnrichment
Updated Feb 6, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 31, 2019
GHSA-3GM7-V7VW-866C