Unrestricted File Upload
Discription
Apache Solr is vulnerable to Unrestricted File Upload. The vulnerability is due to the ConfigSets API accepting and uploading jar/class files without proper restriction of file type. When backing up Solr Collections, the configSet files will be saved to disk, but if the backup directory is included in the applications ClassPath/ClassLoaders, an attacker can use the uploaded classes in any…Read More
References
Back to Main