[SECURITY] CVE-2019-12401: XML Bomb in Apache Solr versions prior to 5.0
Tomas Fernandez Lobbe <[email protected]> Mon, 9 Sep 2019 15:04:31 -0700
| Newsgroups | gmane.comp.jakarta.lucene.solr.user,gmane.comp.apache.maven.announce,gmane.comp.apache.webservices.general,gmane.comp.java.activemq.devel |
|---|---|
| Message-ID | <CAECwjAXU4=kAo5DeUJw7Kvk67sgCmajAN7LGZQNjbjZ8gv=Bdw@mail.gmail.com> |
--000000000000998c63059225f98b Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Severity: Medium Vendor: The Apache Software Foundation Versions Affected: 1.3.0 to 1.4.1 3.1.0 to 3.6.2 4.0.0 to 4.10.4 Description: Solr versions prior to 5.0.0 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it=E2=80=99s update handler. By le= veraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs Mitigation: * Upgrade to Apache Solr 5.0 or later. * Ensure your network settings are configured so that only trusted traffic is allowed to post documents to the running Solr instances. Credit: Matei "Mal" Badanoiu References: [1] https://issues.apache.org/jira/browse/SOLR-13750 [2] https://wiki.apache.org/solr/SolrSecurity --000000000000998c63059225f98b--