In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apache
Published: 2019-03-07T00:00:00
Updated: 2020-12-09T10:06:10
Reserved: 2018-11-14T00:00:00
Link: CVE-2019-0192
JSON object: View
NVD Information
Status : Modified
Published: 2019-03-07T21:29:00.203
Modified: 2023-11-07T03:01:47.513
Link: CVE-2019-0192
JSON object: View
Redhat Information
No data.
CWE