CVE-2013-6408

The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:4.0.0:alpha:*:*:*:*:*:*
cpe:2.3:a:apache:solr:4.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:apache:solr:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:4.2.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:59

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2013-1844.html - () http://rhn.redhat.com/errata/RHSA-2013-1844.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0029.html - () http://rhn.redhat.com/errata/RHSA-2014-0029.html -
References () http://secunia.com/advisories/55542 - Vendor Advisory () http://secunia.com/advisories/55542 - Vendor Advisory
References () http://secunia.com/advisories/59372 - () http://secunia.com/advisories/59372 -
References () http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup - () http://svn.apache.org/viewvc/lucene/dev/branches/branch_4x/solr/CHANGES.txt?view=markup -
References () http://www.openwall.com/lists/oss-security/2013/11/29/2 - () http://www.openwall.com/lists/oss-security/2013/11/29/2 -
References () https://issues.apache.org/jira/browse/SOLR-4881 - Patch () https://issues.apache.org/jira/browse/SOLR-4881 - Patch

07 Nov 2023, 02:17

Type Values Removed Values Added
Summary The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407. The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407.

Information

Published : 2013-12-07 20:55

Updated : 2024-11-21 01:59


NVD link : CVE-2013-6408

Mitre link : CVE-2013-6408

CVE.ORG link : CVE-2013-6408


JSON object : View

Products Affected

apache

  • solr