CVE-2021-27905

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 94.75 % (99th)
94.75% Progress
Affected Products 1
Advisories 1

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

Weaknesses
CWE-918
Server-Side Request Forgery (SSRF)
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2021-04-13 07:15:12
(3 years ago)
Updated Date
2023-11-07 03:32:02
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Solr prior 8.8.2 version cpe:2.3:a:apache:solr < 8.8.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...