Vulnerability Description
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Solr | >= 1.3.0, <= 1.4.1 |
Related Weaknesses (CWE)
References
- http://mail-archives.us.apache.org/mod_mbox/www-announce/201909.mbox/%3CCAECwjAXBroken LinkMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2019/09/10/1Mailing ListThird Party Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-12401-XML%20BoExploitThird Party Advisory
- https://lists.apache.org/thread.html/048ae6e4f84a88e8856f766320b48ad91f9fca2c6f6
- https://lists.apache.org/thread.html/0ec231c5ed8d242890e21806d25fdd47f80cc47cac2
- https://lists.apache.org/thread.html/1c92300643f48f13bc59b15e3f886ba62bae1798c7d
- https://lists.apache.org/thread.html/521d10a19bfb590f86dff41820ccfb11e92281f233a
- https://lists.apache.org/thread.html/60a924662ead9aeea74e8ea128d9ca935f8de925aa7
- https://lists.apache.org/thread.html/7ab5e95a1a0b4f35ffe53f1eb0cb74b4348b49d41b7
- https://lists.apache.org/thread.html/db8eaca456d03c00a66cbe37548978318d424b9997e
- https://security.netapp.com/advisory/ntap-20190926-0002/Third Party Advisory
- http://mail-archives.us.apache.org/mod_mbox/www-announce/201909.mbox/%3CCAECwjAXBroken LinkMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2019/09/10/1Mailing ListThird Party Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-12401-XML%20BoExploitThird Party Advisory
- https://lists.apache.org/thread.html/048ae6e4f84a88e8856f766320b48ad91f9fca2c6f6
FAQ
What is CVE-2019-12401?
CVE-2019-12401 is a vulnerability with a CVSS score of 7.5 (HIGH). Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY ty...
How severe is CVE-2019-12401?
CVE-2019-12401 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12401?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Solr.