Vulnerability Description
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Solr | >= 1.3.0, <= 7.6.0 |
Related Weaknesses (CWE)
References
- http://mail-archives.apache.org/mod_mbox/www-announce/201902.mbox/%3CCAECwjAVjBNMailing ListMitigationVendor Advisory
- http://www.securityfocus.com/bid/107026Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/43026507844ada1ac658ccf7bc939378c13e492fd65
- https://lists.apache.org/thread.html/75dc651478f9d04505b46d44fe3ac739e7aaf3d7bf1
- https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551
- https://lists.apache.org/thread.html/ca3105b6934ccd28e843dffe39724f6963ff49825e9
- https://lists.apache.org/thread.html/e0f9c652b57a91fdcc287efcead620af9f4d8e46b88
- https://lists.apache.org/thread.html/rc400db37710ee79378b6c52de3640493ff538c2beb
- https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b
- https://security.netapp.com/advisory/ntap-20190327-0003/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://mail-archives.apache.org/mod_mbox/www-announce/201902.mbox/%3CCAECwjAVjBNMailing ListMitigationVendor Advisory
- http://www.securityfocus.com/bid/107026Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/43026507844ada1ac658ccf7bc939378c13e492fd65
FAQ
What is CVE-2017-3164?
CVE-2017-3164 is a vulnerability with a CVSS score of 7.5 (HIGH). Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the ser...
How severe is CVE-2017-3164?
CVE-2017-3164 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3164?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Solr.