Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-8307

XXE Vulnerability

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Fixed
    • 5.3
    • 5.4, 6.0
    • Admin UI
    • None

    Description

      Use the drop-down in the left menu to select a core. Use the “Watch Changes” feature under the “Plugins / Stats” option. When submitting the changes, XML is passed in the “stream.body” parameter and is vulnerable to XXE.

      Attachments

        1. SOLR-8307.patch
          8 kB
          Erik Hatcher
        2. SOLR-8307.patch
          1 kB
          Shawn Heisey

        Activity

          People

            ehatcher Erik Hatcher
            adam.johnson Adam Johnson
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: