PT-2013-1141 · Apache · Apache Solr

Uwe Schindler

·

Publicado

2013-12-07

·

Atualizado

2023-02-13

·

CVE-2013-6397

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Solr versions prior to 4.6
Description The issue allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to "solr/select/", when the response writer (wt parameter) is set to XSLT. This can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries. The vulnerability may lead to a violation of confidentiality and availability of protected information.
Recommendations For Apache Solr versions prior to 4.6, consider updating to version 4.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "solr/select/" endpoint or disabling the XSLT response writer to minimize the risk of exploitation. Avoid using the tr parameter with untrusted input in the affected API endpoint until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04135
CVE-2013-6397
DSA-2963-1
GHSA-J8QW-MWMV-28CG

Produtos afetados

Apache Solr