{"id":"GHSA-4p5m-gvpf-f3x5","summary":"Apache Solr Relative Path Traversal vulnerability","details":"Relative Path Traversal vulnerability in Apache Solr.\n\nSolr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the \"configset upload\" API.  Commonly known as a \"zipslip\", maliciously constructed ZIP files can use relative filepaths to write data to unanticipated parts of the filesystem.  \nThis issue affects Apache Solr: from 6.6 through 9.7.0.\n\nUsers are recommended to upgrade to version 9.8.0, which fixes the issue.  Users unable to upgrade may also safely prevent the issue by using Solr's \"Rule-Based Authentication Plugin\" to restrict access to the configset upload API, so that it can only be accessed by a trusted set of administrators/users.","aliases":["BIT-solr-2024-52012","CVE-2024-52012"],"modified":"2026-09-10T03:50:56.351285543Z","published":"2025-01-27T09:30:35Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-01-27T17:22:43Z","nvd_published_at":"2025-01-27T09:15:14Z","cwe_ids":["CWE-23"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52012"},{"type":"WEB","url":"https://github.com/apache/solr/commit/5795edd143b8fcb2ffaf7f278a099b8678adf396"},{"type":"PACKAGE","url":"https://github.com/apache/solr"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/SOLR-17543"},{"type":"WEB","url":"https://lists.apache.org/thread/yp39pgbv4vf1746pf5yblz84lv30vfxd"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/01/26/2"}],"affected":[{"package":{"name":"org.apache.solr:solr-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.solr/solr-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.6"},{"fixed":"9.8.0"}]}],"versions":["6.6.0","6.6.1","6.6.2","6.6.3","6.6.4","6.6.5","6.6.6","7.0.0","7.0.1","7.1.0","7.2.0","7.2.1","7.3.0","7.3.1","7.4.0","7.5.0","7.6.0","7.7.0","7.7.1","7.7.2","7.7.3","8.0.0","8.1.0","8.1.1","8.10.0","8.10.1","8.11.0","8.11.1","8.11.2","8.11.3","8.11.4","8.2.0","8.3.0","8.3.1","8.4.0","8.4.1","8.5.0","8.5.1","8.5.2","8.6.0","8.6.1","8.6.2","8.6.3","8.7.0","8.8.0","8.8.1","8.8.2","8.9.0","9.0.0","9.1.0","9.1.1","9.2.0","9.2.1","9.3.0","9.4.0","9.4.1","9.5.0","9.6.0","9.6.1","9.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-4p5m-gvpf-f3x5/GHSA-4p5m-gvpf-f3x5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}