[SECURITY] CVE-2019-12401: XML Bomb in Apache Solr versions prior to 5.0

Tomas Fernandez Lobbe <[email protected]> Mon, 9 Sep 2019 15:04:31 -0700
Newsgroups gmane.comp.jakarta.lucene.solr.user,gmane.comp.apache.maven.announce,gmane.comp.apache.webservices.general,gmane.comp.java.activemq.devel
Message-ID <CAECwjAXU4=kAo5DeUJw7Kvk67sgCmajAN7LGZQNjbjZ8gv=Bdw@mail.gmail.com>
--000000000000998c63059225f98b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Severity: Medium

Vendor: The Apache Software Foundation

Versions Affected:
1.3.0 to 1.4.1
3.1.0 to 3.6.2
4.0.0 to 4.10.4

Description: Solr versions prior to 5.0.0 are vulnerable to an XML resource
consumption attack (a.k.a. Lol Bomb) via it=E2=80=99s update handler. By le=
veraging
XML DOCTYPE and ENTITY type elements, the attacker can create a pattern
that will expand when the server parses the XML causing OOMs

Mitigation:
* Upgrade to Apache Solr 5.0 or later.
* Ensure your network settings are configured so that only trusted traffic
is allowed to post documents to the running Solr instances.

Credit: Matei "Mal" Badanoiu

References:
[1] https://issues.apache.org/jira/browse/SOLR-13750
[2] https://wiki.apache.org/solr/SolrSecurity

--000000000000998c63059225f98b--