Privilege Escalation Vulnerability in Solr by Apache
CVE-2025-24814
5.4MEDIUM
Summary
Users operating Solr instances with the FileSystemConfigSetService component in an unauthenticated environment face a significant privilege escalation risk. This vulnerability allows the replacement of 'trusted' configuration set files with unvetted alternatives, enabling potential manipulation of Solr's classpath and the execution of malicious code through plugins. To mitigate this issue, it is crucial to enable authentication and authorization in Solr clusters or transition to SolrCloud, along with upgrading to version 9.8.0 or later, which disables the use of '' tags by default.
Affected Version(s)
Apache Solr 0 <= 9.7
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
pwn null