Privilege Escalation Vulnerability in Solr by Apache
CVE-2025-24814
Currently unrated
Summary
Users operating Solr instances with the FileSystemConfigSetService component in an unauthenticated environment face a significant privilege escalation risk. This vulnerability allows the replacement of 'trusted' configuration set files with unvetted alternatives, enabling potential manipulation of Solr's classpath and the execution of malicious code through plugins. To mitigate this issue, it is crucial to enable authentication and authorization in Solr clusters or transition to SolrCloud, along with upgrading to version 9.8.0 or later, which disables the use of '' tags by default.
Affected Version(s)
Apache Solr 0 <= 9.7
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
pwn null