漏洞描述 【漏洞对象】Apache Solr 【涉及版本】Apache Solr before 7.1.0 【漏洞描述】该漏洞可用于任何参数为deftype =xmlparser的查询请求,并且可以利用该漏洞将恶意数据上传到/ upload请求处理程序,或者使用ftp作为BlindXXE包装器,以便从Solr服务器读取任意本地文件
相关漏洞推荐 CVE-2019-17558: Apache Solr Velocity Template RCE solr-file-read: Apache Solr <= 8.8.1 Arbitrary File Read Apache Solr /solr/admin/cores XML 外部实体注入漏洞(CVE-2017-12629) POC CVE-2017-12629: Apache Solr <= 7.1 - XML Entity Injection POC CVE-2019-0192: Apache Solr - Deserialization of Untrusted Data POC CVE-2019-0193: Apache Solr DataImportHandler <8.2.0 - Remote Code Execution POC CVE-2019-17558: Apache Solr <=8.3.1 - Remote Code Execution POC CVE-2021-27905: Apache Solr <=8.8.1 - Server-Side Request Forgery POC CVE-2023-50290: Apache Solr - Host Environment Variables Leak via Metrics API POC CVE-2024-45216: Apache Solr - Authentication Bypass POC CVE-2017-12629: Apache Solr <= 7.1 XML entity injection POC CVE-2019-0193: Apache Solr Remote Code Execution POC CVE-2021-27905: Apache Solr <= 8.8.1 SSRF