Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-16949

RCE via Backup/Restore APIs - Fix for all file extensions

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Fixed
    • 8.11.2
    • 8.11.3, 9.5, 9.4.1
    • Backup/Restore
    • None

    Description

      Before an 8.11.3 release, https://issues.apache.org/jira/browse/SOLR-16480 needs to be backported, thus creating this as a blocker.

      Here I am assuming that 8.x is vulnerable to the same attack, which should be investigated.

      Attachments

        1. SOLR-16949.patch
          29 kB
          Jan Høydahl
        2. SOLR-16949-8_11.patch
          26 kB
          Jan Høydahl
        3. SOLR-16949-8_11-1.patch
          28 kB
          Jan Høydahl
        4. SOLR-16949-main-protect-lib.patch
          15 kB
          Houston Putman
        5. SOLR-16949-main-protect-lib-1.patch
          15 kB
          Houston Putman
        6. SOLR-16949-main-protect-lib-2.patch
          16 kB
          Houston Putman
        7. SOLR-16949-8_11-2.patch
          28 kB
          Jan Høydahl
        8. SOLR-16949-8_11-3.patch
          29 kB
          Jan Høydahl
        9. SOLR-16949-1.patch
          42 kB
          Jan Høydahl
        10. jenkins.log.txt.gz
          39 kB
          Jason Gerlowski
        11. SOLR-16949-inputstream-leaks.patch
          12 kB
          Jan Høydahl

        Issue Links

          Activity

            People

              janhoy Jan Høydahl
              janhoy Jan Høydahl
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: