Privilege Escalation Vulnerability in Solr by Apache
CVE-2025-24814
5.4MEDIUM
What is CVE-2025-24814?
Users operating Solr instances with the FileSystemConfigSetService component in an unauthenticated environment face a significant privilege escalation risk. This vulnerability allows the replacement of 'trusted' configuration set files with unvetted alternatives, enabling potential manipulation of Solr's classpath and the execution of malicious code through plugins. To mitigate this issue, it is crucial to enable authentication and authorization in Solr clusters or transition to SolrCloud, along with upgrading to version 9.8.0 or later, which disables the use of '' tags by default.
Affected Version(s)
Apache Solr 0 <= 9.7