CVE-2018-8026
Description
This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. The manipulated files can be uploaded as configsets using Solrs API, allowing to exploit that vulnerability.
Risk Information
Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
4.341
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2018-8026 are fixed in Apache-solr-core 6.6.5 | Windows |
| Vulnerabilities CVE-2018-8026 are fixed in Apache-solr-core 7.4.0 | Windows |
| Multiple Vulnerabilities are affected in Netapp Snapcenter - | Windows |
| Vulnerabilities CVE-2018-8026 are fixed in Apache-solr-core for Linux 6.6.5 | Linux |
| Vulnerabilities CVE-2018-8026 are fixed in Apache-solr-core for Linux 7.4.0 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234