5
CVSSv2

CVE-2018-1308

Published: 09/04/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache solr

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #896604 lucene-solr: CVE-2018-1308 XXE in DataImportHandler Package: lucene-solr; Maintainer for lucene-solr is Debian Java Maintainers &lt;pkg-java-maintainers@listsaliothdebianorg&gt;; Reported by: Markus Koschany &lt;apo@debianorg&gt; Date: Sun, 22 Apr 2018 19:18:01 UTC Severity: grave Tags: secur ...
An XML external entity expansion vulnerability was discovered in the DataImportHandler of Solr, a search server based on Lucene, which could result in information disclosure For the oldstable distribution (jessie), this problem has been fixed in version 362+dfsg-5+deb8u2 For the stable distribution (stretch), this problem has been fixed in vers ...