PT-2013-1141 · Apache · Apache Solr
Uwe Schindler
·
Published
2013-12-07
·
Updated
2023-02-13
·
CVE-2013-6397
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Solr versions prior to 4.6
Description
The issue allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the
tr parameter to "solr/select/", when the response writer (wt parameter) is set to XSLT. This can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries. The vulnerability may lead to a violation of confidentiality and availability of protected information.Recommendations
For Apache Solr versions prior to 4.6, consider updating to version 4.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "solr/select/" endpoint or disabling the XSLT response writer to minimize the risk of exploitation. Avoid using the
tr parameter with untrusted input in the affected API endpoint until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Solr