CVE-2020-13941

HIGH8.8EPSS 2.0%

Improper Input Validation in Apache Solr

Published: 2/10/2022Modified: 12/6/2023
Also known as:GHSA-2467-h365-j7hmBIT-solr-2020-13941DEBIAN-CVE-2020-13941

Description

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e you could read/write to any location the solr user can access.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (9)