Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-17558

KEV EPSS 94.47% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-17558

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Solr 注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Solr是美国阿帕奇(Apache)基金会的一款基于Lucene(一款全文搜索引擎)的搜索服务器。该产品支持层面搜索、垂直搜索、高亮显示搜索结果等。 Apache Solr 5.0.0版本至8.3.1版本中存在注入漏洞。攻击者可借助Velocity模板利用该漏洞在系统上执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-Apache Solr Apache Solr 5.0.0 to Apache Solr 8.3.1 -

II. Public POCs for CVE-2019-17558

#POC DescriptionSource LinkShenlong Link
1CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.https://github.com/SDNDTeam/CVE-2019-17558_Solr_Vul_ToolPOC Details
2Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340https://github.com/zhzyker/exphubPOC Details
3Solr_CVE-2019-17558https://github.com/Ma1Dong/Solr_CVE-2019-17558POC Details
4Apache Solr 1.4 Injection to get a shellhttps://github.com/xkyrage/Exploit_CVE-2019-17558-RCEPOC Details
5CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.https://github.com/thelostworldFree/CVE-2019-17558_Solr_Vul_ToolPOC Details
6Apache Solr versions 5.0.0 to 8.3.1 are vulnerable to remote code execution vulnerabilities through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/ directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17558.yamlPOC Details
7Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20Solr%20Velocity%20%E6%B3%A8%E5%85%A5%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2019-17558.mdPOC Details
8https://github.com/vulhub/vulhub/blob/master/solr/CVE-2019-17558/README.mdPOC Details
9Nonehttps://github.com/rogerzeferino/Apache-Solr-RCE-CVE-2019-17558POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-17558

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-12-30 · 65 CVEs total

CVE-2018-20493GitLab 安全漏洞
CVE-2019-20165GPAC 代码问题漏洞
CVE-2019-20162GPAC 缓冲区错误漏洞
CVE-2019-20163GPAC 代码问题漏洞
CVE-2019-20164GPAC 代码问题漏洞
CVE-2018-20498GitLab 访问控制错误漏洞
CVE-2018-20497GitLab 代码问题漏洞
CVE-2018-20496GitLab 跨站脚本漏洞
CVE-2018-20495GitLab 信息泄露漏洞
CVE-2018-20494GitLab 访问控制错误漏洞
CVE-2018-20499GitLab 代码问题漏洞
CVE-2018-20491GitLab 跨站脚本漏洞
CVE-2018-20490GitLab 跨站脚本漏洞
CVE-2018-20489GitLab 授权问题漏洞
CVE-2018-20488GitLab 信息泄露漏洞
CVE-2018-7859D-Link DGS-1510 跨站脚本漏洞
CVE-2019-19032XMLBlueprint 代码问题漏洞
CVE-2019-19031Easy XML Editor 代码问题漏洞
CVE-2019-20149kind-of 注入漏洞
CVE-2019-13445ROS communications-related packages 输入验证错误漏洞

Showing top 20 of 65 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-17558

No comments yet


Leave a comment