Lucene search

K
f5F5F5:K50133242
HistoryJul 23, 2021 - 12:00 a.m.

K50133242 : Apache Solr vulnerability CVE-2019-17558

2021-07-2300:00:00
my.f5.com
99

7.6 High

AI Score

Confidence

High

0.975 High

EPSS

Percentile

100.0%

Security Advisory Description

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset velocity/ directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting params.resource.loader.enabled by defining a response writer with that setting set to true. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is trusted (has been uploaded by an authenticated user). (CVE-2019-17558)

Impact

There is no impact; F5 products are not affected by this vulnerability.