跳转到帖子

Apache Solr Backup/Restore APIs RCE

recommended_posts

发布于
  • Members

Apache Solr Backup/Restore APIs RCE

Disclosed
02/24/2024
Created
04/23/2024

Description

Apache Solr from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1 is affected by an Unrestricted Upload of File with Dangerous Type vulnerability which can result in remote code execution in the context of the user running Apache Solr. When Apache Solr creates a Collection, it will use a specific directory as the classpath and load some classes from it. The backup function of the Collection can export malicious class files uploaded by attackers to the directory, allowing Solr to load custom classes and create arbitrary Java code. Execution can further bypass the Java sandbox configured by Solr, ultimately causing arbitrary command execution.

Author(s)

  • l3yx
  • jheysel-r7

Platform

Linux,Unix

Architectures

cmd

Development

  • Source Code
  • History
  • 查看数 707
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…