S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-17558 Scanner

CVE-2019-17558 scanner - Remote Code Execution (RCE) vulnerability in Apache Solr

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-17558
7.5
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache Solrby n/a
Apache Solr 5.0.0 to Apache Solr 8.3.1
Updated Aug 21, 2026View on NVD →
Detail

Apache Solr is an open-source search platform that is used for indexing and searching data. It is built on top of the Apache Lucene search library and allows developers to easily add search capabilities to their applications. Solr provides powerful features such as faceted search, hit highlighting, and distributed search capabilities. It is used by many companies and organizations to power search functionality on their websites, applications, and data repositories.

One of the vulnerabilities detected in Solr is CVE-2019-17558, which is a remote code execution vulnerability through the VelocityResponseWriter. This vulnerability allows an attacker to execute arbitrary code on the server by providing a malicious Velocity template. The template can be supplied through Velocity templates in a configuration set, or as a parameter. Although parameter-provided templates are disabled by default, they can be enabled by setting the `params.resource.loader.enabled` setting to true.

This vulnerability can lead to serious consequences if it is exploited by an attacker. By executing arbitrary code on the server, an attacker can gain complete control over the system and potentially steal sensitive data, install malware, or launch other attacks. This can have a severe impact on the user data and the reputation of an organization using Solr.

In conclusion, the CVE-2019-17558 vulnerability in Apache Solr is a serious issue that can lead to serious consequences when exploited. It is important for organizations to take the necessary precautions to protect their Solr instances and prevent attacks. By utilizing the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities in their digital assets and stay ahead of potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Upgrade to a newer, patched version of Solr.
  • Do not enable parameter-provided templates on a public-facing Solr instance.
  • Only use trusted configuration sets that have been uploaded by authenticated users.
  • Restrict access to Solr's configuration API, preventing unauthorized access.
  • Implement network monitoring and intrusion detection systems to quickly identify and respond to attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.