Site icon API Security Blog

CVE-2023-50386

A flaw was found in Apache Solr. In the affected versions, ConfigSets accept uploading Java jar and class files through the ConfigSets API. When backing up Solr Collections, these ConfigSet files are saved to the disk when using the LocalFileSystemRepository (the default for backups). If the backup was saved to a directory that Solr uses in its ClassPath/ClassLoaders, the jar and class files are available to use with any trusted or untrusted ConfigSet. This issue may allow an attacker to deploy malicious code on the…Read More

Exit mobile version