CVE-2014-3628: XSS
Published Jan 6, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
Affected Software
23 affected components
Apache SOLR=4.0.0
Apache SOLR=4.0.0-alpha
Apache SOLR=4.0.0-beta
Apache SOLR=4.1.0
Apache SOLR=4.2.0
Apache SOLR=4.2.1
Apache SOLR=4.3.0
Apache SOLR=4.3.1
Apache SOLR=4.4.0
Apache SOLR=4.5.0
Apache SOLR=4.5.1
Apache SOLR=4.6.0
Apache SOLR=4.6.1
Apache SOLR=4.7.0
Apache SOLR=4.7.1
Apache SOLR=4.7.2
Apache SOLR=4.8.0
Apache SOLR=4.8.1
Apache SOLR=4.9.0
Apache SOLR=4.9.1
Apache SOLR=4.10.0
Apache SOLR=4.10.1
Apache SOLR=4.10.2
Event History
Jan 6, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3628?
CVE-2014-3628 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-3628?
To fix CVE-2014-3628, upgrade Apache Solr to version 4.10.3 or later.
3
What type of vulnerability is CVE-2014-3628?
CVE-2014-3628 is a cross-site scripting (XSS) vulnerability affecting the Admin UI Plugin / Stats page in Apache Solr.
4
Which versions of Apache Solr are affected by CVE-2014-3628?
CVE-2014-3628 affects Apache Solr versions 4.0.0 through 4.10.2.
5
Can CVE-2014-3628 be exploited remotely?
Yes, CVE-2014-3628 can be exploited by remote attackers to inject arbitrary web scripts or HTML.