CVE-2019-0193

Click the icon to Follow me:- twitterTelegramRedditDiscord

Summary:

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request’s “dataConfig” parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property “enable.dih.dataConfigParam” to true.

Reference Links(if available):

  • https://issues.apache.org/jira/browse/SOLR-13669
  • https://lists.debian.org/debian-lts-announce/2019/10/msg00013.html
  • https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E
  • https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E
  • https://lists.apache.org/thread.html/[email protected]%3Cissues.lucene.apache.org%3E
  • CVSS Score (if available)

    v2: / MEDIUMAV:N/AC:L/Au:S/C:C/I:C/A:C

    v3: / HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

    Links to Exploits(if available)

  • Available for Amazon Prime