CVE-2020-13957: Critical severity apache solr vulnerability
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13957?
CVE-2020-13957 has a high severity due to its potential for remote code execution.
How do I fix CVE-2020-13957?
To fix CVE-2020-13957, upgrade Apache Solr to a version later than 8.6.2.
Which versions of Apache Solr are affected by CVE-2020-13957?
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3, and 8.0.0 to 8.6.2 are affected by CVE-2020-13957.
What type of vulnerability is CVE-2020-13957?
CVE-2020-13957 is a vulnerability that allows unauthorized configuration of dangerous features in Apache Solr.
Can CVE-2020-13957 be exploited remotely?
Yes, CVE-2020-13957 can be exploited remotely, potentially allowing an attacker to execute arbitrary code.