CVE-2019-0192: Input Validation
A flaw was found in the Apache Solr's Config API, where it would permit the configuration of the JMX server via an HTTP POST request. An attacker could use this flaw to direct traffic to a malicious RMI server, and then trigger remote code execution or conduct further attacks.
Other sources
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-0192.
What is the severity of CVE-2019-0192?
The severity of CVE-2019-0192 is critical with a score of 9.8.
Which software versions are affected by CVE-2019-0192?
Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, as well as Netapp Storage Automation Store, are affected by CVE-2019-0192.
How does CVE-2019-0192 allow remote code execution?
CVE-2019-0192 allows remote code execution by exploiting Solr's unsafe deserialization through a malicious RMI server.
Where can I find more information about CVE-2019-0192?
You can find more information about CVE-2019-0192 in the provided references: [1], [2], [3].