Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3585
HistoryFeb 16, 2017 - 1:56 a.m.

Directory Traversal

2017-02-1601:56:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.005

Percentile

76.8%

Apache Solr is vulnerable to directory traversal attacks. The vulnerability exists because a replication handler provided by Apache Solr supports an HTTP API which does not validate the user supplied file_name parameter. Therefore, attackers can pull index files from a master/leader node using this flaw.