CVE-2013-6407: XEE
The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.solr:solr-coreto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
Apache Solr UpdateRequestHandler (XML)to a version that resolves this vulnerability.Fixed in 4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6407?
CVE-2013-6407 has not been assigned a CVSS score, but it is classified as a significant vulnerability due to its potential for enabling XML External Entity attacks.
How do I fix CVE-2013-6407?
To fix CVE-2013-6407, upgrade to Apache Solr version 4.1.0 or later.
What are the risks associated with CVE-2013-6407?
The risks associated with CVE-2013-6407 include potential remote code execution and data exposure through XML External Entity injection.
Which versions of Apache Solr are affected by CVE-2013-6407?
Apache Solr versions prior to 4.1.0, including 3.6.0, 3.6.1, 3.6.2, and 4.0.0-alpha/beta, are affected by CVE-2013-6407.
Is CVE-2013-6407 related to XML External Entity processing?
Yes, CVE-2013-6407 is specifically an XML External Entity (XXE) issue that arises from improper handling of XML data.