Vulnerability Name: | CVE-2018-8026 (CCN-145827) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2018-07-04 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2018-07-04 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2019-03-29 | ||||||||||||||||||||||||||||||||||||||||
Summary: | This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. The manipulated files can be uploaded as configsets using Solr's API, allowing to exploit that vulnerability. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-611 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-8026 Source: CCN Type: Apache Solr Web site Apache Solr Source: CCN Type: oss-sec Mailing List, Wed, 4 Jul 2018 18:56:35 +0200 CVE-2018-8026: XXE vulnerability due to Apache Solr configset upload (exchange rate provider config / enum field config / TIKA parsecontext) Source: BID Type: Third Party Advisory, VDB Entry 104690 Source: CCN Type: BID-104690 Apache Solr CVE-2018-8026 XML External Entity Multiple Information Disclosure Vulnerabilities Source: XF Type: UNKNOWN apache-cve20188026-info-disc(145827) Source: CCN Type: SOLR-12450 CVE-2018-8026: More XXE vulns in code using DocumentBuilder Source: CONFIRM Type: Exploit, Issue Tracking, Vendor Advisory https://issues.apache.org/jira/browse/SOLR-12450 Source: MLIST Type: Mailing List, Vendor Advisory [lucene-solr-user] 20180704 [SECURITY] CVE-2018-8026: XXE vulnerability due to Apache Solr configset upload (exchange rate provider config / enum field config / TIKA parsecontext) Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20190307-0002/ Source: CCN Type: IBM Security Bulletin 719185 (InfoSphere Information Server) A vulnerability in Apache Solr (lucene) affects IBM InfoSphere Information Server | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |