Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-11482

CVE-2017-12629: Remove RunExecutableListener from Solr


    • Type: Task
    • Status: Closed
    • Priority: Blocker
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 5.5.5, 6.6.2, 7.1, 7.2, 8.0
    • Component/s: security, Server
    • Security Level: Public (Default Security Level. Issues are Public)
    • Labels:


      This class should no longer be needed, as replication can be done through Solr Cloud or via ReplicationHandler. The current listener is a security risk, as it can be configured through the Config API. See the report:

      Solr "RunExecutableListener" class can be used to execute arbitrary commands on specific events, for example after each update query. The problem is that such listener can be enabled with any parameters just by using Config API with add-listener command.

      POST /solr/newcollection/config HTTP/1.1
      Host: localhost:8983
      Connection: close
      Content-Type: application/json  
      Content-Length: 198
        "add-listener" : {

      Parameters "exe", "args" and "dir" can be crafted throught the HTTP request during modification of the collection's config. This means that anybody who can send a HTTP request to Solr API is able to execute arbitrary shell commands when "postCommit" event is fired. It leads to execution of arbitrary remote code for a remote attacker.


        1. SOLR-11482.patch
          39 kB
          Uwe Schindler
        2. SOLR-11482-6.6.patch
          29 kB
          Uwe Schindler
        3. SOLR-11482-branch_5_5-restore-logged-warning.patch
          1 kB
          Steve Rowe



            • Assignee:
              thetaphi Uwe Schindler
              thetaphi Uwe Schindler
            • Votes:
              0 Vote for this issue
              8 Start watching this issue


              • Created: