Lucene search

K
redhatRedHatRHSA-2017:3451
HistoryDec 12, 2017 - 5:19 p.m.

(RHSA-2017:3451) Moderate: rh-java-common-lucene security update

2017-12-1217:19:20
access.redhat.com
24

EPSS

0.974

Percentile

99.9%

Apache Lucene is a high-performance, full-featured text search engine library written entirely in Java. It is a technology suitable for nearly any application that requires full-text search, especially cross-platform.

Security Fix(es):

  • It was discovered that Lucene’s XML query parser did not properly restrict doctype declaration and expansion of external entities. An attacker with access to an application using a Lucene XML query parser could exploit this flaw to perform XML eXternal Entity (XXE) attacks. (CVE-2017-12629)

For more information regarding CVE-2017-12629, see the article linked in the References section.