CVE-2018-8026: XEE
This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. The manipulated files can be uploaded as configsets using Solr's API, allowing to exploit that vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.solr:solr-coreto a version that resolves this vulnerability.Fixed in 7.4.0 - Upgrade
Upgrade
maven/org.apache.solr:solr-coreto a version that resolves this vulnerability.Fixed in 6.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8026?
The severity of CVE-2018-8026 is medium with a CVSS score of 5.5.
What is the affected software for CVE-2018-8026?
The affected software for CVE-2018-8026 is Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1, as well as Netapp Snapcenter and Netapp Storage Automation Store.
What is the description of CVE-2018-8026?
CVE-2018-8026 is a vulnerability in Apache Solr that relates to an XML external entity expansion (XXE) in Solr config files, and it also affects Netapp Snapcenter and Netapp Storage Automation Store.
How can I fix CVE-2018-8026?
To fix CVE-2018-8026, you should upgrade to a fixed version of Apache Solr, such as 6.6.5 or 7.3.2, and ensure that XML external entity (XXE) processing is disabled.
Where can I find more information about CVE-2018-8026?
You can find more information about CVE-2018-8026 on the following references: [http://www.securityfocus.com/bid/104690](http://www.securityfocus.com/bid/104690), [https://issues.apache.org/jira/browse/SOLR-12450](https://issues.apache.org/jira/browse/SOLR-12450), [https://mail-archives.apache.org/mod_mbox/lucene-solr-user/201807.mbox/%3C0cdc01d413b7%24f97ba580%24ec72f080%24%40apache.org%3E](https://mail-archives.apache.org/mod_mbox/lucene-solr-user/201807.mbox/%3C0cdc01d413b7%24f97ba580%24ec72f080%24%40apache.org%3E)