PT-2013-1141 · Apache · Apache Solr

Uwe Schindler

·

Published

2013-12-07

·

Updated

2023-02-13

·

CVE-2013-6397

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Solr versions prior to 4.6
Description The issue allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to "solr/select/", when the response writer (wt parameter) is set to XSLT. This can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries. The vulnerability may lead to a violation of confidentiality and availability of protected information.
Recommendations For Apache Solr versions prior to 4.6, consider updating to version 4.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "solr/select/" endpoint or disabling the XSLT response writer to minimize the risk of exploitation. Avoid using the tr parameter with untrusted input in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2015-04135
CVE-2013-6397
DSA-2963-1
GHSA-J8QW-MWMV-28CG

Affected Products

Apache Solr