CVE-2015-8797: XSS
Published Feb 15, 2016
·Updated
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.
Affected Software
1 affected component
Apache SOLR<=5.3
Event History
Feb 15, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8797?
CVE-2015-8797 is classified with a medium severity due to its potential for cross-site scripting vulnerabilities.
2
How do I fix CVE-2015-8797?
To fix CVE-2015-8797, upgrade Apache Solr to version 5.3.1 or later.
3
What types of attacks are possible with CVE-2015-8797?
CVE-2015-8797 allows remote attackers to execute arbitrary web scripts or HTML in the context of the user's session.
4
In which versions of Apache Solr is CVE-2015-8797 present?
CVE-2015-8797 affects all versions of Apache Solr prior to 5.3.1.
5
What components of Apache Solr does CVE-2015-8797 affect?
CVE-2015-8797 affects the Admin UI, specifically the stats page in webapp/web/js/scripts/plugins.js.