Skip to main content

Vendor/product archive

apache / solr CVEs

Beta · best-effort

46 CVEs tagged to apache / solr9 Critical, 21 High, 15 Medium, 1 Low, 0 Unrated.

CVE-2026-44825

Published Jun 1, 2026

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full a…

CVSS 8.1 · High
evidence mentions
3
Buzz score
35.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-22444

Published Jan 21, 2026

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to rea…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-22022

Published Jan 21, 2026

Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to i…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-24814

Published Jan 27, 2025

Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52012

Published Jan 27, 2025

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45217

Published Oct 16, 2024

Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give i…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45216

Published Oct 16, 2024

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerab…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-50386

Published Feb 9, 2024

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50298

Published Feb 9, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50292

Published Feb 9, 2024

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50291

Published Feb 9, 2024

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50290

Published Jan 15, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44548

Published Dec 23, 2021

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29943

Published Apr 13, 2021

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29262

Published Apr 13, 2021

When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27905

Published Apr 13, 2021

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate anot…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-13957

Published Oct 13, 2020

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13941

Published Aug 17, 2020

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replicat…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11802

Published Apr 1, 2020

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17558

Published Dec 30, 2019

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates…

CVSS 7.5 · High
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-12409

Published Nov 18, 2019

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping w…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2