CVE-2018-1308
Last modified
CVE-2018-1308 is a vulnerability of currently unknown severity. This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.. EPSS estimates a 20.94% chance of exploitation in the next 30 days.
Description
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Solr | >= 1.2, <= 6.6.2 |
| Apache | Solr | >= 7.0.0, <= 7.2.1 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
References
- https://issues.apache.org/jira/browse/SOLR-11971Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00025.htmlThird Party Advisory
- https://mail-archives.apache.org/mod_mbox/www-announce/201804.mbox/%3C000001d3cf68%245ac69af0%241053d0d0%24%40apache.org%3EMitigation, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4194Third Party Advisory
- https://issues.apache.org/jira/browse/SOLR-11971Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00025.htmlThird Party Advisory
- https://mail-archives.apache.org/mod_mbox/www-announce/201804.mbox/%3C000001d3cf68%245ac69af0%241053d0d0%24%40apache.org%3EMitigation, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4194Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1308?
How severe is CVE-2018-1308?
How do I fix CVE-2018-1308?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-13074The mintToken function of a smart contract implementation fo…
- CVE-2018-13075The mintToken function of a smart contract implementation fo…7.5
- CVE-2018-13076The mintToken function of a smart contract implementation fo…
- CVE-2018-13077The mintToken function of a smart contract implementation fo…
- CVE-2018-13078The mintToken function of a smart contract implementation fo…
- CVE-2018-13079The mintToken function of a smart contract implementation fo…
- CVE-2018-13080The mintToken function of a smart contract implementation fo…
- CVE-2018-13081The mintToken function of a smart contract implementation fo…7.5
- CVE-2018-13082The mintToken function of a smart contract implementation fo…7.5
- CVE-2018-13083The mintToken function of a smart contract implementation fo…7.5
- CVE-2018-13084The mintToken function of a smart contract implementation fo…7.5
- CVE-2018-13085The mintToken function of a smart contract implementation fo…
Are you affected by CVE-2018-1308?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
