漏洞描述 Apache Solr是美国阿帕奇(Apache)基金会的一款基于Lucene(一款全文搜索引擎)的搜索服务器。该产品支持层面搜索、垂直搜索、高亮显示搜索结果等。Apache Solr 5.0.0版本至8.3.1版本中存在注入漏洞。攻击者可借助Velocity模板利用该漏洞在系统上执行任意代码。
相关漏洞推荐 CVE-2019-17558: Apache Solr Velocity Template RCE solr-file-read: Apache Solr <= 8.8.1 Arbitrary File Read Apache Solr /solr/admin/cores XML 外部实体注入漏洞(CVE-2017-12629) POC CVE-2017-12629: Apache Solr <= 7.1 - XML Entity Injection POC CVE-2019-0192: Apache Solr - Deserialization of Untrusted Data POC CVE-2019-0193: Apache Solr DataImportHandler <8.2.0 - Remote Code Execution POC CVE-2019-17558: Apache Solr <=8.3.1 - Remote Code Execution POC CVE-2021-27905: Apache Solr <=8.8.1 - Server-Side Request Forgery POC CVE-2023-50290: Apache Solr - Host Environment Variables Leak via Metrics API POC CVE-2024-45216: Apache Solr - Authentication Bypass POC CVE-2017-12629: Apache Solr <= 7.1 XML entity injection POC CVE-2019-0193: Apache Solr Remote Code Execution POC CVE-2021-27905: Apache Solr <= 8.8.1 SSRF