XML External Entity Vulnerability in Apache Solr by Apache
CVE-2018-8010
5.5MEDIUM
What is CVE-2018-8010?
The vulnerability in Apache Solr relates to improper handling of XML external entities, enabling attackers to read arbitrary files from the server. This issue affects Solr configuration files (solrconfig.xml, schema.xml, managed-schema) and utilizes XInclude functionality, allowing malicious users to exploit file, FTP, or HTTP protocols. To mitigate the risk, it is recommended to update to releases 6.6.4 or 7.3.1, which restrict access to local files and Zookeeper resources while denying absolute URLs.
Affected Version(s)
Apache Solr Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0