漏洞信息详情
Apache Solr 代码注入漏洞
- CNNVD编号:CNNVD-201908-031
- 危害等级: 高危
- CVE编号: CVE-2019-0193
- 漏洞类型: 代码注入
- 发布时间: 2019-08-01
- 威胁类型: 远程
- 更新时间: 2021-08-05
- 厂 商:
- 漏洞来源:
漏洞简介
Apache Solr是美国阿帕奇(Apache)基金会的一款基于Lucene(一款全文搜索引擎)的搜索服务器。该产品支持层面搜索、垂直搜索、高亮显示搜索结果等。
Apache Solr 8.2.0之前版本中存在代码注入漏洞。攻击者可利用该漏洞在目标服务器上执行恶意代码。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://issues.apache.org/jira/browse/SOLR-13669
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r19d23e8640236a3058b4d6c23e5cd663fde182255f5a9d63e0606a66@%3Cdev.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/9b0e7a7e3e18d0724f511403b364fc082ff56e3134d84cfece1c82fc@%3Cissues.lucene.apache.org%3E
来源:issues.apache.org
链接:https://issues.apache.org/jira/browse/SOLR-13669
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r33aed7ad4ee9833c4190a44e2b106efd2deb19504b85e012175540f6@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/6f2d61bd8732224c5fd3bdd84798f8e01e4542d3ee2f527a52a81b83@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/7143983363f0ba463475be4a8b775077070a08dbf075449b7beb51ee@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/rc400db37710ee79378b6c52de3640493ff538c2beb41cefdbbdf2ab8@%3Ccommits.submarine.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r3da74965aba2b5f5744b7289ad447306eeb2940c872801819faa9314@%3Cusers.solr.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/rb34d820c21f1708c351f9035d6bc7daf80bfb6ef99b34f7af1d2f699@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/1addbb49a1fc0947fb32ca663d76d93cfaade35a4848a76d4b4ded9c@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/a6e3c09dba52b86d3a1273f82425973e1b0623c415d0e4f121d89eab@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/08/msg00025.HTML
来源:MLIST
链接:https://lists.apache.org/thread.HTML/e85f735fad06a0fb46e74b7e6e9ce7ded20b59637cd9f993310f814d@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r95df34bb158375948da82b4dfe9a1b5d528572d586584162f8f5aeef@%3Cusers.solr.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r140128dc6bb4f4e0b6a39e962c7ca25a8cbc8e48ed766176c931fccc@%3Cusers.solr.apache.org%3E
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/10/msg00013.HTML
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1@%3Ccommits.druid.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/55880d48e38ba9e8c41a3b9e41051dbfdef63b86b0cfeb32967edf03@%3Cissues.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/r339865b276614661770c909be1dd7e862232e3ef0af98bfd85686b51@%3Cdev.lucene.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.HTML/42cc4d334ba33905b872a0aa00d6a481391951c8b1450f01b077ce74@%3Cissues.lucene.apache.org%3E
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.3803/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2820/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-0193
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2019-0193
受影响实体
暂无
补丁
- Apache Solr 安全漏洞的修复措施
评论