XML Resource Consumption Vulnerability in Apache Solr
CVE-2019-12401

7.5HIGH

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
10 September 2019

Summary

Apache Solr, in versions 1.3.0 through 4.10.4, is susceptible to an XML resource consumption vulnerability known as an XML bomb, also referred to as a Lol Bomb. This vulnerability exploits XML DOCTYPE and ENTITY type elements, enabling an attacker to create an XML pattern that exponentially expands when parsed by the server's update handler. The result is a significant performance degradation, potentially causing the server to experience out-of-memory (OOM) errors during operation.

Affected Version(s)

Solr 1.3.0 to 1.4.1

Solr 3.1.0 to 3.6.2

Solr 4.0.0 to 4.10.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.