DEBIAN-CVE-2019-17558
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | lucene-solr | 0, 3.6.2+dfsg-27, 3.6.2+dfsg-26 |
| Debian:13 | lucene-solr | 0, 3.6.2+dfsg-27, 3.6.2+dfsg-26 |
| Debian:14 | lucene-solr | 0, 0, 3.6.2+dfsg |
| Debian:11 | lucene-solr | 0, *, 3.6.2+dfsg-27 |
Exploit Intelligence
- rogerzeferino/Apache-Solr-RCE-CVE-2019-17558 (github-poc-repo)
- Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340 (github-poc-repo)
- rogerzeferino/Apache-Solr-RCE-CVE-2019-17558 (github-poc)
- Apache Solr 1.4 Injection to get a shell (github-poc)
- Solr_CVE-2019-17558 (github-poc)
- Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340 (github-poc)
- CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool. (github-poc)
- agent_group.yaml (github-poc)
- kev.json (github-poc)
- web_poc_map_v2.yaml (github-poc)
…and 5 more exploits
Timeline
- Dec 30, 2019 CVE Published
- Apr 28, 2026 CVE Updated