HTTP: Apache Solr Data Import Handler XML External Entity Expansion Information Disclosure

This signature detects attempts to exploit a known vulnerability against Apache Solr. Successful exploitation results in the disclosure of file or directory contents for any file or directory readable by the Apache Solr service.

Extended Description

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.

Affected Products

Apache solr

Short Name
HTTP:APACHE:SOLR-XXE-INFO-DIS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache CVE-2018-1308 Data Disclosure Entity Expansion External Handler Import Information Solr XML
Release Date
04/19/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Apache

Debian

CVSS Score

5.0

Found a potential security threat?