CVE-2017-3164
08.03.2019, 21:29
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
Vendor | Product | Version |
---|---|---|
apache | solr | 1.3.0 ≤ 𝑥 ≤ 7.6.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References