solr: Remote Code Execution through the VelocityResponseWriter
Published Dec 30, 2019 ·Due May 3, 2022
7.5
HIGHCVSS 3.1
EPSS 98.57%
Description
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
Affected products
- Vendor n/a Product Apache Solr Defaultn/a
- Version Apache Solr 5.0.0 to Apache Solr 8.3.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache Solr | n/a |
|
Configuration 1
Configuration 2
- ≥ 17.7 · ≤ 17.12
- 16.1
- 16.2
- 18.8
- 19.12
No data.
Red Hat JBoss Data Virtualization 6
solr-core
Not affected
Red Hat JBoss Enterprise Application Platform 6
solr-core
Not affected
Red Hat JBoss Fuse 6
solr-core
Not affected
Red Hat JBoss Fuse Service Works 6
solr-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Virtualization 6 | solr-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | solr-core | Not affected | n/a |
| Red Hat JBoss Fuse 6 | solr-core | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | solr-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:S/C:P/I:P/A:P
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 6, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 98.57% (0.98567) | 99.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.57% (0.98567) | 99.92th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.46% (0.94460) | 99.99th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.54% (0.97535) | 100.00th | v3 (v2023.03.01) |
| Jun 11, 2024 | 97.51% (0.97511) | 99.99th | v3 (v2023.03.01) |
| May 27, 2024 | 97.52% (0.97525) | 99.99th | v3 (v2023.03.01) |
| Feb 7, 2024 | 97.54% (0.97538) | 99.99th | v3 (v2023.03.01) |
| Jan 6, 2024 | 97.52% (0.97517) | 99.99th | v3 (v2023.03.01) |
| Nov 8, 2023 | 97.51% (0.97507) | 99.98th | v3 (v2023.03.01) |
| Sep 22, 2023 | 97.53% (0.97527) | 99.99th | v3 (v2023.03.01) |
| Jun 4, 2023 | 97.54% (0.97543) | 99.99th | v3 (v2023.03.01) |
| May 19, 2023 | 97.52% (0.97517) | 99.97th | v3 (v2023.03.01) |
| May 4, 2023 | 97.50% (0.97504) | 99.96th | v3 (v2023.03.01) |
| Apr 17, 2023 | 97.52% (0.97518) | 99.97th | v3 (v2023.03.01) |
| Apr 2, 2023 | 97.50% (0.97498) | 99.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.51% (0.97512) | 99.96th | v3 (v2023.03.01) |
| Mar 6, 2023 | 96.09% (0.96094) | 99.99th | v2 (v2022.01.01) |
| Feb 4, 2022 | 96.09% (0.96094) | 99.99th | v2 (v2022.01.01) |
| Feb 3, 2022 | 93.39% (0.93392) | 99.95th | v1 |
| Sep 1, 2021 | 93.39% (0.93392) | 99.98th | v1 |
| Apr 14, 2021 | 93.39% (0.93392) | 0.00th | v1 |
References (64)
- http://packetstormsecurity.com/files/157078/Apache-Solr-8.3.0-Velocity-Template-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-17558 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1789509 Issue Tracking
- https://github.com/advisories/GHSA-ww97-9w65-2crx Advisory
- https://github.com/apache/lucene-solr/pull/1156
- https://issues.apache.org/jira/browse/SOLR-13971 x_refsource_MISCExploitIssue TrackingPatchVendor Advisory
- https://issues.apache.org/jira/browse/SOLR-14025
- https://lists.apache.org/thread.html/r0b7b9d4113e6ec1ae1d3d0898c645f758511107ea44f0f3a1210c5d5%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r0b7b9d4113e6ec1ae1d3d0898c645f758511107ea44f0f3a1210c5d5@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r12ab2cb15a34e49b4fecb5b2bdd7e10f3e8b7bf1f4f47fcde34d3a7c%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r12ab2cb15a34e49b4fecb5b2bdd7e10f3e8b7bf1f4f47fcde34d3a7c@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r19d23e8640236a3058b4d6c23e5cd663fde182255f5a9d63e0606a66%40%3Cdev.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r19d23e8640236a3058b4d6c23e5cd663fde182255f5a9d63e0606a66@%3Cdev.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r25f1bd4545617f5b86dde27b4c30fec73117af65598a30e20209739a%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r25f1bd4545617f5b86dde27b4c30fec73117af65598a30e20209739a@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r339865b276614661770c909be1dd7e862232e3ef0af98bfd85686b51%40%3Cdev.lucene.apache.org%3E mailing-listx_refsource_MLISTIssue TrackingMailing List
- https://lists.apache.org/thread.html/r339865b276614661770c909be1dd7e862232e3ef0af98bfd85686b51@%3Cdev.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r36e35fd76239a381643555966fb3e72139e018d52d76544fb42f96d8%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTIssue TrackingMailing List
- https://lists.apache.org/thread.html/r36e35fd76239a381643555966fb3e72139e018d52d76544fb42f96d8@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r5074d814d3a8c75df4b20e66bfd268ee0a73ddea7e85070cec3ae78d%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTExploitMailing List
- https://lists.apache.org/thread.html/r5074d814d3a8c75df4b20e66bfd268ee0a73ddea7e85070cec3ae78d@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r58c58fe51c87bc30ee13bb8b4c83587f023edb349018705208e65b37%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r58c58fe51c87bc30ee13bb8b4c83587f023edb349018705208e65b37@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r5dc200f7337093285bac40e6d5de5ea66597c3da343a0f7553f1bb12%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r5dc200f7337093285bac40e6d5de5ea66597c3da343a0f7553f1bb12@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r79c7e75f90e735fd32c4e3e97340625aab66c09dfe8c4dc0ab768b69%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r79c7e75f90e735fd32c4e3e97340625aab66c09dfe8c4dc0ab768b69@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r7b89b3dcfc1b6c52dd8d610b897ac98408245040c92b484fe97a51a2%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r7b89b3dcfc1b6c52dd8d610b897ac98408245040c92b484fe97a51a2@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r7f21ab40a9b17b1a703db84ac56773fcabacd4cc1eb5c4700d17c071%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r7f21ab40a9b17b1a703db84ac56773fcabacd4cc1eb5c4700d17c071@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r8a36e4f92f4449dec517e560e1b55639f31b3aca26c37bbad45e31de%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r8a36e4f92f4449dec517e560e1b55639f31b3aca26c37bbad45e31de@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r8e7a3c253a695a7667da0b0ec57f9bb0e31f039e62afbc00a1d96f7b%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r8e7a3c253a695a7667da0b0ec57f9bb0e31f039e62afbc00a1d96f7b@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r9271d030452170ba6160c022757e1b5af8a4c9ccf9e04164dec02e7f%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r9271d030452170ba6160c022757e1b5af8a4c9ccf9e04164dec02e7f@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r99c3f7ec3a079e2abbd540ecdb55a0e2a0f349ca7084273a12e87aeb%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r99c3f7ec3a079e2abbd540ecdb55a0e2a0f349ca7084273a12e87aeb@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/ra29fa6ede5184385bf2c63e8ec054990a7d4622bba1d244bee70d82d%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/ra29fa6ede5184385bf2c63e8ec054990a7d4622bba1d244bee70d82d@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/rafc939fdd753f55707841cd5886fc7fcad4d8d8ba0c72429b3220a9a%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/rafc939fdd753f55707841cd5886fc7fcad4d8d8ba0c72429b3220a9a@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/rb964fe5c4e3fc05f75e8f74bf6b885f456b7a7750c36e9a8045c627a%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/rb964fe5c4e3fc05f75e8f74bf6b885f456b7a7750c36e9a8045c627a@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/rc400db37710ee79378b6c52de3640493ff538c2beb41cefdbbdf2ab8%40%3Ccommits.submarine.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/rc400db37710ee79378b6c52de3640493ff538c2beb41cefdbbdf2ab8@%3Ccommits.submarine.apache.org%3E
- https://lists.apache.org/thread.html/rde3dbd8e646dabf8bef1b097e9a13ee0ecbdb8441aaed6092726c98d%40%3Cissues.ambari.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/rde3dbd8e646dabf8bef1b097e9a13ee0ecbdb8441aaed6092726c98d@%3Cissues.ambari.apache.org%3E
- https://lists.apache.org/thread.html/re8d12db916b5582a23ed144b9c5abd0bea0be1649231aa880f6cbfff%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/re8d12db916b5582a23ed144b9c5abd0bea0be1649231aa880f6cbfff@%3Cissues.lucene.apache.org%3E
- https://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55%40%3Csolr-user.lucene.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/rf5230a049d989dbfdd404b4320a265dceeeba459a4d04ec21873bd55@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/rf6d7ffae2b940114324e036b6394beadf27696d051ae0c4a5edf07af%40%3Cissues.lucene.apache.org%3E mailing-listx_refsource_MLISTExploitMailing List
- https://lists.apache.org/thread.html/rf6d7ffae2b940114324e036b6394beadf27696d051ae0c4a5edf07af@%3Cissues.lucene.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2019-17558
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-17558 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2019-17558
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.