[MAVEN:GHSA-MX2H-HF7J-2X3P] Improper Neutralization of Input During Web Page Generation in Apache Solr

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.

Package Affected Version
pkg:maven/org.apache.solr/solr-core < 5.1.0
Package Fixed Version
pkg:maven/org.apache.solr/solr-core = 5.1.0
ID
MAVEN:GHSA-MX2H-HF7J-2X3P
Severity
moderate
URL
https://github.com/advisories/GHSA-mx2h-hf7j-2x3p
Published
2022-05-17T03:59:03
(2 years ago)
Modified
2023-01-27T05:02:23
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.solr/solr-core org.apache.solr solr-core < 5.1.0
Fixed pkg:maven/org.apache.solr/solr-core org.apache.solr solr-core = 5.1.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...