Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 19% | — | JdomApache SolrApache TikaDebian Linux+2 | 16/6/2021 | 17/6/2026 | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | |
| Modificada | Crítica (9.1) | 4.7% | — | Apache Solr | 13/4/2021 | 17/6/2026 | When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization resolution on the receiving hosts. | |
| Modificada | Alta (7.5) | 6.7% | — | Apache Solr | 13/4/2021 | 17/6/2026 | When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable.… | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Apache Solr | 13/4/2021 | 17/6/2026 | The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to… | |
| Modificada | Baja (2.7) | 4.2% | — | Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+19 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. | |
| Modificada | Media (5.3) | 78% | 💥 PoC | Eclipse JettyApache NifiApache SparkNetapp E-series Santricity OS Controller+12 | 26/2/2021 | 17/6/2026 | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values,… | |
| Modificada | Alta (8.8) | 4.4% | — | Apache HadoopApache SolrOracle Financial Services Crime AND Compliance Management Studio | 26/1/2021 | 17/6/2026 | In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification. | |
| Modificada | Crítica (9.8) | 79% | 💥 PoC | Apache Solr | 13/10/2020 | 17/6/2026 | Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be… | |
| Modificada | Alta (8.8) | 3.9% | 💥 PoC | Apache Solr | 17/8/2020 | 17/6/2026 | Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location… | |
| Analizada | Media (4.3) | 2.0% | — | Apache Solr | 1/4/2020 | 17/6/2026 | In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serves the request. Solr bypasses all authorization settings for… | |
| Analizada | Alta (7.5) | 99% | ⚠ Explotación activa💥 Exploit | Apache SolrOracle Primavera Unifier | 30/12/2019 | 17/6/2026 | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious,… | |
| Modificada | Crítica (9.8) | 21% | 💥 PoC | Apache Solr | 18/11/2019 | 17/6/2026 | The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT… | |
| Modificada | Alta (7.5) | 8.5% | 💥 PoC | Apache Solr | 10/9/2019 | 17/6/2026 | Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs. | |
| Analizada | Alta (7.2) | 84% | ⚠ Explotación activa💥 Exploit | Apache SolrDebian Linux | 1/8/2019 | 17/6/2026 | In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a… | |
| Modificada | Alta (7.5) | 19% | 💥 PoC | Apache Solr | 8/3/2019 | 17/6/2026 | Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL. | |
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Apache SolrNetapp Storage Automation Store | 7/3/2019 | 17/6/2026 | In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side. | |
| Modificada | Media (5.5) | 9.0% | — | Apache SolrNetapp SnapcenterNetapp Storage Automation Store | 5/7/2018 | 17/6/2026 | This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a… | |
| Modificada | Media (5.5) | 3.8% | — | Apache Solr | 21/5/2018 | 17/6/2026 | This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as… | |
| Modificada | Alta (7.5) | 21% | — | Apache SolrDebian Linux | 9/4/2018 | 17/6/2026 | This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal… | |
| Analizada | Crítica (9.1) | 4.7% | — | Apache SolrSimplexml Project Simplexml | 17/11/2017 | 17/6/2026 | SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on. | |
| Modificada | Crítica (9.8) | 92% | 💥 Exploit | Apache SolrRedhat Jboss Enterprise Application PlatformDebian LinuxCanonical Ubuntu Linux | 14/10/2017 | 17/6/2026 | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion… | |
| Modificada | Alta (7.5) | 2.2% | — | Apache Solr | 18/9/2017 | 17/6/2026 | Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this functionality (when using SecurityAwareZkACLProvider type of ACL provider e.g. SaslZkACLProvider). Firstly, access to… | |
| Modificada | Alta (7.5) | 6.6% | — | Apache Solr | 30/8/2017 | 17/6/2026 | When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any… | |
| Modificada | Alta (7.5) | 5.6% | — | Apache Solr | 7/7/2017 | 17/6/2026 | Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster and point it to a malicious node. This can trick the nodes in cluster to believe that the malicious node is a member of… | |
| Modificada | Media (6.1) | 4.5% | 💥 Exploit | Wpsolr-search-engine | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin wpsolr-search-engine v7.6 |