Vulnerabilities > CVE-2012-6612 - Unspecified vulnerability in Apache Solr
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apache
nessus
Summary
The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | Apache
| 22 |
Nessus
NASL family | CGI abuses |
NASL id | SOLR_4_1_0.NASL |
description | The version of Apache Solr running on the remote web server is affected by multiple XML external entity injection vulnerabilities because the XML parser accepts XML data containing external entity declarations from untrusted sources. A remote, unauthenticated attacker can exploit this flaw to gain access to arbitrary files or to cause a denial of service condition. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 71844 |
published | 2014-01-07 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/71844 |
title | Apache Solr < 4.1.0 Multiple XML External Entity Injections |
code |
|
Redhat
advisories |
|
References
- http://rhn.redhat.com/errata/RHSA-2013-1844.html
- http://rhn.redhat.com/errata/RHSA-2013-1844.html
- http://rhn.redhat.com/errata/RHSA-2014-0029.html
- http://rhn.redhat.com/errata/RHSA-2014-0029.html
- http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup
- http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup
- https://issues.apache.org/jira/browse/SOLR-3895
- https://issues.apache.org/jira/browse/SOLR-3895