← Back to CVE List
Vulnerability Intelligence Report
SSRF vulnerability with the Replication handler

CVE-2021-27905

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

Nuclei Template
CVSS Base Score
9.8
CRITICAL
EPSS Probability:93.05%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-918 ↗CWE-918 Server-Side Request Forgery (SSRF)

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache Solr Apache Solr < 8.8.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
93.053%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2021-03-02T00:00:00
Published2021-04-13T06:35:20
Last Updated2024-08-03T21:33:16

LINK COPIED TO CLIPBOARD