Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Solr | Apache Solr ~ 8.8.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Apache Solr SSRF(CVE-2021-27905) | https://github.com/Henry4E36/Solr-SSRF | POC Details |
| 2 | CVE-2021-27905 | https://github.com/W2Ning/Solr-SSRF | POC Details |
| 3 | [CVE-2021-27905] Apache Solr ReplicationHandler Server Side Request Forgery (SSRF) | https://github.com/murataydemir/CVE-2021-27905 | POC Details |
| 4 | POC for LFI related to CVE-2021-27905 | https://github.com/pdelteil/CVE-2021-27905.POC | POC Details |
| 5 | Apache Solr versions 8.8.1 and prior contain a server-side request forgery vulnerability. The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27905.yaml | POC Details |
| 6 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20Solr%20Replication%20handler%20SSRF%20CVE-2021-27905.md | POC Details |
| 7 | Apache Solr < 8.8.2 Server Side Request Forgery | https://github.com/RIZZZIOM/CVE-2021-27905 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-29262 | Misapplied Zookeeper ACLs can result in leakage of configured authentication and authoriza | |
| CVE-2021-29943 | Apache Solr Unprivileged users may be able to perform unauthorized read/write to collectio | |
| CVE-2021-29425 | Possible limited path traversal vulnerabily in Apache Commons IO |
No comments yet