{"id":"GHSA-3pph-2595-cgfh","summary":"There is a XML external entity expansion (XXE) vulnerability in Apache Solr ","details":"This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=\u003cinlinexml\u003e` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network.","aliases":["CVE-2018-1308"],"modified":"2024-03-04T20:46:19.149385Z","published":"2018-10-17T19:55:46Z","database_specific":{"github_reviewed_at":"2020-06-16T20:55:43Z","nvd_published_at":null,"cwe_ids":["CWE-611"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1308"},{"type":"WEB","url":"https://github.com/apache/lucene-solr/commit/3530397f1777332872eac2760f9aa0e2ae1d7450"},{"type":"WEB","url":"https://github.com/apache/lucene-solr/commit/739a7933"},{"type":"WEB","url":"https://github.com/apache/lucene-solr/commit/dd3be31f7062dcb2f3b2d7f0e89df29e197dee63"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3pph-2595-cgfh"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SOLR-11971"},{"type":"WEB","url":"https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/04/msg00025.html"},{"type":"WEB","url":"https://mail-archives.apache.org/mod_mbox/www-announce/201804.mbox/%3C000001d3cf68%245ac69af0%241053d0d0%24%40apache.org%3E"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4194"}],"affected":[{"package":{"name":"org.apache.solr:solr-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.solr/solr-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2"},{"fixed":"6.6.3"}]}],"versions":["1.3.0","1.4.0","1.4.1","3.1.0","3.2.0","3.3.0","3.4.0","3.5.0","3.6.0","3.6.1","3.6.2","4.0.0","4.0.0-ALPHA","4.0.0-BETA","4.1.0","4.10.0","4.10.1","4.10.2","4.10.3","4.10.4","4.2.0","4.2.1","4.3.0","4.3.1","4.4.0","4.5.0","4.5.1","4.6.0","4.6.1","4.7.0","4.7.1","4.7.2","4.8.0","4.8.1","4.9.0","4.9.1","5.0.0","5.1.0","5.2.0","5.2.1","5.3.0","5.3.1","5.3.2","5.4.0","5.4.1","5.5.0","5.5.1","5.5.2","5.5.3","5.5.4","5.5.5","6.0.0","6.0.1","6.1.0","6.2.0","6.2.1","6.3.0","6.4.0","6.4.1","6.4.2","6.5.0","6.5.1","6.6.0","6.6.1","6.6.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-3pph-2595-cgfh/GHSA-3pph-2595-cgfh.json"}},{"package":{"name":"org.apache.solr:solr-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.solr/solr-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.3.0"}]}],"versions":["7.0.0","7.0.1","7.1.0","7.2.0","7.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-3pph-2595-cgfh/GHSA-3pph-2595-cgfh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}