Apache Solr: Configset upload on Windows allows arbitrary path write-access
Published Jan 27, 2025
6.6
MEDIUMCVSS 4.0
EPSS 44.99%
Description
Relative Path Traversal vulnerability in Apache Solr.
Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API. Commonly known as a "zipslip", maliciously constructed ZIP files can use relative filepaths to write data to unanticipated parts of the filesystem. This issue affects Apache Solr: from 6.6 through 9.7.0.
Users are recommended to upgrade to version 9.8.0, which fixes the issue. Users unable to upgrade may also safely prevent the issue by using Solr's "Rule-Based Authentication Plugin" to restrict access to the configset upload API, so that it can only be accessed by a trusted set of administrators/users.
Affected products
-
- Version 6.6StatusaffectedConstraints<=9.7.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Solr | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jan 27, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 44.99% (0.44993) | 98.74th | v5 (v2026.06.15) |
| Sep 17, 2026 | 44.99% (0.44993) | 98.72th | v5 (v2026.06.15) |
| Jul 6, 2026 | 47.21% (0.47207) | 98.69th | v5 (v2026.06.15) |
| Jun 25, 2026 | 43.31% (0.43312) | 98.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 41.23% (0.41226) | 98.48th | v5 (v2026.06.15) |
| Mar 7, 2026 | 13.48% (0.13483) | 94.07th | v4 (v2025.03.14) |
| Mar 6, 2026 | 9.91% (0.09908) | 92.89th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.22% (0.02220) | 83.97th | v4 (v2025.03.14) |
| Nov 18, 2025 | 3.30% (0.03304) | 86.00th | v4 (v2025.03.14) |
| Nov 13, 2025 | 2.22% (0.02220) | 83.96th | v4 (v2025.03.14) |
| Jul 7, 2025 | 1.12% (0.01116) | 77.20th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.10% (0.00101) | 24.95th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.14% (0.01143) | 65.43th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.07% (0.00075) | 20.00th | v4 (v2025.03.14) |
| Jan 28, 2025 | 0.04% (0.00043) | 11.45th | v3 (v2023.03.01) |
References (6)
- http://www.openwall.com/lists/oss-security/2025/01/26/2 Mailing ListThird Party Advisory
- https://github.com/advisories/GHSA-4p5m-gvpf-f3x5 Advisory
- https://github.com/apache/solr/commit/5795edd143b8fcb2ffaf7f278a099b8678adf396
- https://issues.apache.org/jira/browse/SOLR-17543
- https://lists.apache.org/thread/yp39pgbv4vf1746pf5yblz84lv30vfxd vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-52012
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/01/26/2 | Mailing ListThird Party Advisory | |
| https://github.com/advisories/GHSA-4p5m-gvpf-f3x5 | Advisory | |
| https://github.com/apache/solr/commit/5795edd143b8fcb2ffaf7f278a099b8678adf396 | ||
| https://issues.apache.org/jira/browse/SOLR-17543 | ||
| https://lists.apache.org/thread/yp39pgbv4vf1746pf5yblz84lv30vfxd | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-52012 |
Change history (0)
No recorded changes yet.