Lucene search

K
redhatcveRedhat.comRH:CVE-2019-0193
HistoryDec 20, 2019 - 3:14 p.m.

CVE-2019-0193

2019-12-2015:14:42
redhat.com
access.redhat.com
17

0.959 High

EPSS

Percentile

99.5%

A flaw was found in Apache Solr’s DataImportHandler(DIH). A DIH configuration containing scripts coming from a request’s dataConfig parameter allows an attacker to perform remote code execution.

Mitigation

Edit solrconfig.xml to configure all DataImportHandler usages with an "invariants" section listing the "dataConfig" parameter set to am empty string, or ensure your network settings are configured so that only trusted traffic communicates with Solr, especially to the DataImportHandler (although this is a best practice regardless) (ref: <https://issues.apache.org/jira/browse/SOLR-13669&gt;)