Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22106
HistoryDec 05, 2019 - 7:43 a.m.

Remote Code Execution (RCE)

2019-12-0507:43:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.975

Percentile

100.0%

solr-velocity is vulnerable to remote code execution (RCE). The vulnerability can be caused by loading custom Velocity templates containing malicious code since the solr resource loader in VelocityResponseWriter.java was on by default.

References