First published: Wed Jan 29 2020(Updated: )
Michael Stepankin and Olga Barinova discovered that Apache Solr was vulnerable to an XXE attack. An attacker could use this vulnerability to remotely execute code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/liblucene3-contrib-java | <3.6.2+dfsg-8ubuntu0.1 | 3.6.2+dfsg-8ubuntu0.1 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/liblucene3-java | <3.6.2+dfsg-8ubuntu0.1 | 3.6.2+dfsg-8ubuntu0.1 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/libsolr-java | <3.6.2+dfsg-8ubuntu0.1 | 3.6.2+dfsg-8ubuntu0.1 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/solr-common | <3.6.2+dfsg-8ubuntu0.1 | 3.6.2+dfsg-8ubuntu0.1 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/solr-jetty | <3.6.2+dfsg-8ubuntu0.1 | 3.6.2+dfsg-8ubuntu0.1 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/solr-tomcat | <3.6.2+dfsg-8ubuntu0.1 | 3.6.2+dfsg-8ubuntu0.1 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4259-1 has a high severity rating due to the potential for remote code execution through an XXE attack.
To fix USN-4259-1, update to the patched version 3.6.2+dfsg-8ubuntu0.1 of the affected libraries.
USN-4259-1 affects Apache Solr and several related Java libraries in Ubuntu 16.04.
USN-4259-1 is an XML External Entity (XXE) vulnerability.
Yes, exploitation of USN-4259-1 can allow an attacker to execute code remotely, potentially leading to data breaches.