Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12629
HistoryJan 15, 2019 - 9:19 a.m.

Remote Code Execution (RCE)

2019-01-1509:19:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.974

Percentile

99.9%

lucene-queryparser is vulnerable to remote code execution. This is possible through the use of an XML external entity expansion (XXE) attack and the Config API with add-listener command

References