ID:2051 - Exploit for Exposed dangerous method or function in Apache Solr - CVE-2019-0193

 
Main Vulnerability Database Exploits ID:2051 - Exploit for Exposed dangerous method or function in Apache Solr - CVE-2019-0193

ID:2051 - Exploit for Exposed dangerous method or function in Apache Solr - CVE-2019-0193

Published: March 18, 2020


Vulnerability identifier: #VU20062
Vulnerability risk: Medium
CVE-ID: CVE-2019-0193
CWE-ID: CWE-749
Exploitation vector: Remote access
Vulnerable software:
Apache Solr

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to DataImportHandler module in Apache Solr has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. A remote attacker can send a specially crafted reuqest to the affected application and execute arbitrary code on the target system.



Remediation

Install updates from vendor's website.