Lucene search

K
nvd[email protected]NVD:CVE-2017-3163
HistoryAug 30, 2017 - 2:29 p.m.

CVE-2017-3163

2017-08-3014:29:00
CWE-22
web.nvd.nist.gov
5

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.8

Confidence

High

EPSS

0.005

Percentile

76.8%

When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.

Affected configurations

Nvd
Node
apachesolrRange5.5.3
OR
apachesolrMatch6.0.0
OR
apachesolrMatch6.0.1
OR
apachesolrMatch6.1.0
OR
apachesolrMatch6.2.0
OR
apachesolrMatch6.2.1
OR
apachesolrMatch6.3.0
OR
apachesolrMatch6.4.0
VendorProductVersionCPE
apachesolr*cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*
apachesolr6.0.0cpe:2.3:a:apache:solr:6.0.0:*:*:*:*:*:*:*
apachesolr6.0.1cpe:2.3:a:apache:solr:6.0.1:*:*:*:*:*:*:*
apachesolr6.1.0cpe:2.3:a:apache:solr:6.1.0:*:*:*:*:*:*:*
apachesolr6.2.0cpe:2.3:a:apache:solr:6.2.0:*:*:*:*:*:*:*
apachesolr6.2.1cpe:2.3:a:apache:solr:6.2.1:*:*:*:*:*:*:*
apachesolr6.3.0cpe:2.3:a:apache:solr:6.3.0:*:*:*:*:*:*:*
apachesolr6.4.0cpe:2.3:a:apache:solr:6.4.0:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.8

Confidence

High

EPSS

0.005

Percentile

76.8%