Apache Solr
Apache · 26 CVEs
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
Jun 1, 2026
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
Jan 21, 2026
Apache Solr: Insufficient file-access checking in standalone core-creation requests
Jan 21, 2026
Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files
Jan 27, 2025
Apache Solr: Configset upload on Windows allows arbitrary path write-access
Jan 27, 2025
Apache Solr: ConfigSets created during a backup restore command are trusted implicitly
Oct 16, 2024
Apache Solr: Authentication bypass possible using a fake URL Path ending
Oct 16, 2024
Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords
Feb 9, 2024
Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users
Feb 9, 2024
Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions
Feb 9, 2024
Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
Feb 9, 2024
Apache Solr: Host environment variables are published via the Metrics API
Jan 15, 2024
Apache Solr information disclosure vulnerability through DataImportHandler
Dec 23, 2021
Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections
Apr 13, 2021
Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings
Apr 13, 2021
SSRF vulnerability with the Replication handler
Apr 13, 2021
solr: Information disclosure via Rule-base Authorization plugin
Apr 1, 2020
solr: Remote Code Execution via DataImportHandler
Aug 1, 2019
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not h…
Mar 8, 2019
solr: remote code execution due to unsafe deserialization
Mar 7, 2019
solr: XML external entity expansion in config files allows for arbitrary file read
Jul 5, 2018
solr: XML external entity expansion in config files allows attackers to read arbitrary files
May 21, 2018
Solr: XML external entity expansion in handler/dataimport/DataImporter.java allows remote attackers to read arbitrary f…
Apr 9, 2018
solr: Kerberos delegation token functionality allows to re-use authentication
Sep 18, 2017
solr: Directory traversal via Index Replication HTTP API
Aug 30, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-44825 | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users | CRITICAL | 2.84% | Jun 1, 2026 |
| CVE-2026-22022 | Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin | HIGH | 0.57% | Jan 21, 2026 |
| CVE-2026-22444 | Apache Solr: Insufficient file-access checking in standalone core-creation requests | HIGH | 0.73% | Jan 21, 2026 |
| CVE-2025-24814 | Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files | HIGH | 1.17% | Jan 27, 2025 |
| CVE-2024-52012 | Apache Solr: Configset upload on Windows allows arbitrary path write-access | MEDIUM | 44.99% | Jan 27, 2025 |
| CVE-2024-45217 | Apache Solr: ConfigSets created during a backup restore command are trusted implicitly | HIGH | 0.74% | Oct 16, 2024 |
| CVE-2024-45216 | Apache Solr: Authentication bypass possible using a fake URL Path ending | CRITICAL | 92.75% | Oct 16, 2024 |
| CVE-2023-50291 | Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords | HIGH | 3.28% | Feb 9, 2024 |
| CVE-2023-50292 | Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users | HIGH | 3.02% | Feb 9, 2024 |
| CVE-2023-50298 | Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions | MEDIUM | 1.56% | Feb 9, 2024 |
| CVE-2023-50386 | Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets | HIGH | 83.72% | Feb 9, 2024 |
| CVE-2023-50290 | Apache Solr: Host environment variables are published via the Metrics API | MEDIUM | 68.45% | Jan 15, 2024 |
| CVE-2021-44548 | Apache Solr information disclosure vulnerability through DataImportHandler | CRITICAL | 5.07% | Dec 23, 2021 |
| CVE-2021-29943 | Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections | CRITICAL | 4.67% | Apr 13, 2021 |
| CVE-2021-29262 | Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings | HIGH | 6.72% | Apr 13, 2021 |
| CVE-2021-27905 | SSRF vulnerability with the Replication handler | CRITICAL | 93.05% | Apr 13, 2021 |
| CVE-2018-11802 | solr: Information disclosure via Rule-base Authorization plugin | MEDIUM | 2.02% | Apr 1, 2020 |
| CVE-2019-0193 KEV | solr: Remote Code Execution via DataImportHandler | HIGH | 83.55% | Aug 1, 2019 |
| CVE-2017-3164 | Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism,… | HIGH | 19.44% | Mar 8, 2019 |
| CVE-2019-0192 | solr: remote code execution due to unsafe deserialization | CRITICAL | 78.23% | Mar 7, 2019 |
| CVE-2018-8026 | solr: XML external entity expansion in config files allows for arbitrary file read | MEDIUM | 9.03% | Jul 5, 2018 |
| CVE-2018-8010 | solr: XML external entity expansion in config files allows attackers to read arbitrary files | MEDIUM | 3.78% | May 21, 2018 |
| CVE-2018-1308 | Solr: XML external entity expansion in handler/dataimport/DataImporter.java allows remote attackers to read arbitrary files | HIGH | 20.82% | Apr 9, 2018 |
| CVE-2017-9803 | solr: Kerberos delegation token functionality allows to re-use authentication | HIGH | 2.19% | Sep 18, 2017 |
| CVE-2017-3163 | solr: Directory traversal via Index Replication HTTP API | HIGH | 6.56% | Aug 30, 2017 |
Showing 1 to 25 of 26 CVEs