Apache Solr

Apache · 26 CVEs

CVE-2026-44825
CRITICAL

Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users

Jun 1, 2026

CVE-2026-22022
HIGH

Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin

Jan 21, 2026

CVE-2026-22444
HIGH

Apache Solr: Insufficient file-access checking in standalone core-creation requests

Jan 21, 2026

CVE-2025-24814
HIGH

Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files

Jan 27, 2025

CVE-2024-52012
MEDIUM

Apache Solr: Configset upload on Windows allows arbitrary path write-access

Jan 27, 2025

CVE-2024-45217
HIGH

Apache Solr: ConfigSets created during a backup restore command are trusted implicitly

Oct 16, 2024

CVE-2024-45216
CRITICAL

Apache Solr: Authentication bypass possible using a fake URL Path ending

Oct 16, 2024

CVE-2023-50291
HIGH

Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords

Feb 9, 2024

CVE-2023-50292
HIGH

Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users

Feb 9, 2024

CVE-2023-50298
MEDIUM

Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions

Feb 9, 2024

CVE-2023-50386
HIGH

Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets

Feb 9, 2024

CVE-2023-50290
MEDIUM

Apache Solr: Host environment variables are published via the Metrics API

Jan 15, 2024

CVE-2021-44548
CRITICAL

Apache Solr information disclosure vulnerability through DataImportHandler

Dec 23, 2021

CVE-2021-29943
CRITICAL

Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections

Apr 13, 2021

CVE-2021-29262
HIGH

Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings

Apr 13, 2021

CVE-2021-27905
CRITICAL

SSRF vulnerability with the Replication handler

Apr 13, 2021

CVE-2018-11802
MEDIUM

solr: Information disclosure via Rule-base Authorization plugin

Apr 1, 2020

CVE-2019-0193
KEV HIGH

solr: Remote Code Execution via DataImportHandler

Aug 1, 2019

CVE-2017-3164
HIGH

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not h…

Mar 8, 2019

CVE-2019-0192
CRITICAL

solr: remote code execution due to unsafe deserialization

Mar 7, 2019

CVE-2018-8026
MEDIUM

solr: XML external entity expansion in config files allows for arbitrary file read

Jul 5, 2018

CVE-2018-8010
MEDIUM

solr: XML external entity expansion in config files allows attackers to read arbitrary files

May 21, 2018

CVE-2018-1308
HIGH

Solr: XML external entity expansion in handler/dataimport/DataImporter.java allows remote attackers to read arbitrary f…

Apr 9, 2018

CVE-2017-9803
HIGH

solr: Kerberos delegation token functionality allows to re-use authentication

Sep 18, 2017

CVE-2017-3163
HIGH

solr: Directory traversal via Index Replication HTTP API

Aug 30, 2017

Showing 1 to 25 of 26 CVEs