Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5281
HistoryOct 16, 2017 - 12:44 a.m.

Remote Code Execution (RCE)

2017-10-1600:44:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.974

Percentile

99.9%

lucene-queryparser is vulnerable to remote code execution (RCE). This is possible through the use of an XML external entity expansion (XXE) attack and the Config API with add-listener command

References