XML Resource Consumption Vulnerability in Apache Solr
CVE-2019-12401
7.5HIGH
Summary
Apache Solr, in versions 1.3.0 through 4.10.4, is susceptible to an XML resource consumption vulnerability known as an XML bomb, also referred to as a Lol Bomb. This vulnerability exploits XML DOCTYPE and ENTITY type elements, enabling an attacker to create an XML pattern that exponentially expands when parsed by the server's update handler. The result is a significant performance degradation, potentially causing the server to experience out-of-memory (OOM) errors during operation.
Affected Version(s)
Solr 1.3.0 to 1.4.1
Solr 3.1.0 to 3.6.2
Solr 4.0.0 to 4.10.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved