CVE-2017-3164
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
- Affected products
- Apache Solr, Debian
- Apache Solr
- ≤ 7.6.0
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 19.4% (97th percentile)
- Weakness
- CWE-918
- NVD status
- Modified
- Published
- 2019-03-08
CVE-2017-3164 at NVD
1 known exploit for CVE-2017-3164
Proof-of-concept code and exploit modules indexed by Sploitus