CVE-2014-3628

Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
apachesolr
4.0.0
apachesolr
4.0.0:alpha
apachesolr
4.0.0:beta
apachesolr
4.1.0
apachesolr
4.2.0
apachesolr
4.2.1
apachesolr
4.3.0
apachesolr
4.3.1
apachesolr
4.4.0
apachesolr
4.5.0
apachesolr
4.5.1
apachesolr
4.6.0
apachesolr
4.6.1
apachesolr
4.7.0
apachesolr
4.7.1
apachesolr
4.7.2
apachesolr
4.8.0
apachesolr
4.8.1
apachesolr
4.9.0
apachesolr
4.9.1
apachesolr
4.10.0
apachesolr
4.10.1
apachesolr
4.10.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
lucene-solr
bullseye
3.6.2+dfsg-24
fixed
sid
3.6.2+dfsg-26
fixed
trixie
3.6.2+dfsg-26
fixed
bookworm
3.6.2+dfsg-26
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lucene-solr
artful
not-affected
zesty
ignored
yakkety
ignored
xenial
not-affected
wily
ignored
vivid
ignored
utopic
ignored
trusty
not-affected
precise
dne
lucid
dne