Privilege Escalation Vulnerability in Solr by Apache
CVE-2025-24814

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
27 January 2025

Summary

Users operating Solr instances with the FileSystemConfigSetService component in an unauthenticated environment face a significant privilege escalation risk. This vulnerability allows the replacement of 'trusted' configuration set files with unvetted alternatives, enabling potential manipulation of Solr's classpath and the execution of malicious code through plugins. To mitigate this issue, it is crucial to enable authentication and authorization in Solr clusters or transition to SolrCloud, along with upgrading to version 9.8.0 or later, which disables the use of '' tags by default.

Affected Version(s)

Apache Solr 0 <= 9.7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pwn null
.