4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
0.02 Low
EPSS
Percentile
88.8%
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats
page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject
arbitrary web script or HTML via the fieldvaluecache object.
Author | Note |
---|---|
sbeattie | only affected solr 4.x releases |
mail-archives.us.apache.org/mod_mbox/www-announce/201412.mbox/%[email protected]%3E
secunia.com/advisories/62024
issues.apache.org/jira/browse/SOLR-6738
launchpad.net/bugs/cve/CVE-2014-3628
nvd.nist.gov/vuln/detail/CVE-2014-3628
security-tracker.debian.org/tracker/CVE-2014-3628
www.cve.org/CVERecord?id=CVE-2014-3628