CVE-2019-17558
Last modified
CVE-2019-17558 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. CISA has confirmed active exploitation in the wild. EPSS estimates a 98.57% chance of exploitation in the next 30 days.
Description
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Solr | >= 5.0.0, < 7.7.3 |
| Apache | Solr | >= 8.0.0, < 8.4.0 |
| Oracle | Primavera Unifier | >= 17.7, <= 17.12 |
| Oracle | Primavera Unifier | 16.1 |
| Oracle | Primavera Unifier | 16.2 |
| Oracle | Primavera Unifier | 18.8 |
| Oracle | Primavera Unifier | 19.12 |
References
- http://packetstormsecurity.com/files/157078/Apache-Solr-8.3.0-Velocity-Template-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/SOLR-13971Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- http://packetstormsecurity.com/files/157078/Apache-Solr-8.3.0-Velocity-Template-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://issues.apache.org/jira/browse/SOLR-13971Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-17558US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2019-17558?
How severe is CVE-2019-17558?
How do I fix CVE-2019-17558?
Are you affected by CVE-2019-17558?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
