org.apache.solr:solr-parent
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.solr:solr-parentpage 1 of 1
- CVE-2018-11802MEDIUMCVSS 4.3EG 4.3✓ Fixed in 6.6.62020-04-01
vulnerable: 1.3.0 ... 6.6.5 (68 versions)
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a re…
- CVE-2020-13941HIGHCVSS 8.8EG 8.8✓ Fixed in 8.6.02020-08-17
vulnerable: 1.3.0 ... 8.5.2 (94 versions)
Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allow…
- CVE-2020-13957CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.6.32020-10-13
vulnerable: 6.6.0 ... 8.6.2 (35 versions)
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authenticati…
- CVE-2021-27905CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.8.22021-04-13
vulnerable: 1.3.0 ... 8.8.1 (101 versions)
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate ind…
- CVE-2021-29943CRITICALCVSS 9.1EG 9.1✓ Fixed in 8.8.22021-04-13
vulnerable: 1.3.0 ... 8.8.1 (101 versions)
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorre…
- CVE-2021-44548CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.11.12021-12-23
vulnerable: 1.3.0 ... 8.9.0 (106 versions)
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker …
Check whether org.apache.solr:solr-parent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.solr:solr-parent CVEs against the assets you own.
Start Free Scan →