Apache / Solr
47 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44825 | Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users | CRITICAL | 9.8 | Jun 1, 2026 |
| CVE-2026-22022 | Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin | HIGH | 8.2 | Jan 21, 2026 |
| CVE-2026-22444 | Apache Solr: Insufficient file-access checking in standalone core-creation requests | HIGH | 7.1 | Jan 21, 2026 |
| CVE-2025-24814 | Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files | HIGH | 7.2 | Jan 27, 2025 |
| CVE-2024-52012 | Apache Solr: Configset upload on Windows allows arbitrary path write-access | MEDIUM | 6.6 | Jan 27, 2025 |
| CVE-2024-45217 | Apache Solr: ConfigSets created during a backup restore command are trusted implicitly | HIGH | 8.1 | Oct 16, 2024 |
| CVE-2024-45216 | Apache Solr: Authentication bypass possible using a fake URL Path ending | CRITICAL | 9.3 | Oct 16, 2024 |
| CVE-2023-50291 | Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords | HIGH | 7.5 | Feb 9, 2024 |
| CVE-2023-50292 | Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users | HIGH | 7.5 | Feb 9, 2024 |
| CVE-2023-50298 | Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions | MEDIUM | 6.9 | Feb 9, 2024 |
| CVE-2023-50386 | Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets | HIGH | 8.8 | Feb 9, 2024 |
| CVE-2023-50290 | Apache Solr: Host environment variables are published via the Metrics API | MEDIUM | 6.5 | Jan 15, 2024 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2021-44548 | Apache Solr information disclosure vulnerability through DataImportHandler | CRITICAL | 9.8 | Dec 23, 2021 |
| CVE-2021-33813 | jdom: XXE allows attackers to cause a DoS via a crafted HTTP request | HIGH | 7.5 | Jun 16, 2021 |
| CVE-2021-29943 | Apache Solr Unprivileged users may be able to perform unauthorized read/write to collections | CRITICAL | 9.1 | Apr 13, 2021 |
| CVE-2021-29262 | Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settings | HIGH | 7.5 | Apr 13, 2021 |
| CVE-2021-27905 | SSRF vulnerability with the Replication handler | CRITICAL | 9.8 | Apr 13, 2021 |
| CVE-2021-28163 | jetty: Symlink directory exposes webapp directory contents | LOW | 2.7 | Apr 1, 2021 |
| CVE-2020-27223 | jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS | MEDIUM | 5.3 | Feb 26, 2021 |
| CVE-2020-9492 | hadoop: WebHDFS client might send SPNEGO authorization header | HIGH | 8.8 | Jan 26, 2021 |
| CVE-2020-13957 | solr: The checks added to unauthenticated configset uploads can be circumvented | CRITICAL | 9.8 | Oct 13, 2020 |
| CVE-2020-13941 | solr: replication handler allows a read-write operations to any location the solr user can access | MEDIUM | 8.8 | Aug 17, 2020 |
| CVE-2018-11802 | solr: Information disclosure via Rule-base Authorization plugin | MEDIUM | 4.3 | Apr 1, 2020 |
| CVE-2019-17558 KEV | solr: Remote Code Execution through the VelocityResponseWriter | HIGH | 7.5 | Dec 30, 2019 |
Showing 1 to 25 of 47 CVEs