CVE-2019-0193
Apache Solr DataImportHandler Code Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
YesDecision
Descriptions
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
En Solr de Apache, el DataImportHandler, un módulo opcional pero popular para extraer datos de bases de datos y otras fuentes, presenta una funcionalidad en la que toda la configuración de DIH puede provenir del parámetro "dataConfig" de una petición. El modo de depuración de la pantalla de administración DIH utiliza esto para permitir la depuración y desarrollo conveniente de una configuración DIH. Puesto que una configuración DIH puede contener scripts, este parámetro es un riesgo de seguridad. A partir de la versión 8.2.0 de Solr, el uso de este parámetro requiere ajustar la propiedad del Sistema Java "enable.dih.dataConfigParam" en true.
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-14 CVE Reserved
- 2019-03-18 First Exploit
- 2019-08-01 CVE Published
- 2021-12-10 Exploited in Wild
- 2022-06-10 KEV Due Date
- 2024-07-25 EPSS Updated
- 2024-08-04 CVE Updated
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (25)
URL | Date | SRC |
---|---|---|
https://github.com/jas502n/CVE-2019-0193 | 2019-08-12 | |
https://github.com/xConsoIe/CVE-2019-0193 | 2019-03-18 | |
https://github.com/jaychouzzk/CVE-2019-0193-exp | 2019-09-04 |
URL | Date | SRC |
---|---|---|
https://issues.apache.org/jira/browse/SOLR-13669 | 2024-07-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Solr Search vendor "Apache" for product "Solr" | < 7.7.3 Search vendor "Apache" for product "Solr" and version " < 7.7.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Solr Search vendor "Apache" for product "Solr" | >= 8.1.0 < 8.1.2 Search vendor "Apache" for product "Solr" and version " >= 8.1.0 < 8.1.2" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|