[SECURITY] CVE-2017-3164 SSRF issue in Apache Solr
Tomas Fernandez Lobbe <[email protected]> Tue, 12 Feb 2019 11:43:49 -0800
| Newsgroups | gmane.comp.apache.commons.general,gmane.comp.apache.maven.announce,gmane.comp.java.wicket.devel,gmane.comp.jakarta.lucene.solr.user |
|---|---|
| Message-ID | <CAECwjAVjBN=wO5rYs6ktAX-5=-f5JDFwbbTSM2TTjEbGO5jKKA__44447.0257776388$1550000651$gmane$org@mail.gmail.com> |
--000000000000995f2e0581b7a566 Content-Type: text/plain; charset="UTF-8" CVE-2017-3164 SSRF issue in Apache Solr Severity: High Vendor: The Apache Software Foundation Versions Affected: Apache Solr versions from 1.3 to 7.6.0 Description: The "shards" parameter does not have a corresponding whitelist mechanism, so it can request any URL. Mitigation: Upgrade to Apache Solr 7.7.0 or later. Ensure your network settings are configured so that only trusted traffic is allowed to ingress/egress your hosts running Solr. Credit: dk from Chaitin Tech References: https://issues.apache.org/jira/browse/SOLR-12770 https://wiki.apache.org/solr/SolrSecurity --000000000000995f2e0581b7a566--