[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2020-13941 -- lucene-solr

ID: oval:org.secpod.oval:def:2003947Date: (C)2020-10-08   (M)2023-11-13
Class: VULNERABILITYFamily: unix




Reported in SOLR-14515 and fixed in SOLR-14561 , released in Solr version 8.6.0. The Replication handler allows commands backup, restore and deleteBackup. Each of these take a location parameter, which was not validated, i.e you could read/write to any location the solr user can access.

Platform:
Debian 10.x
Debian 9.x
Product:
liblucene3-java
Reference:
CVE-2020-13941
CVE    1
CVE-2020-13941
CPE    3
cpe:/a:apache:liblucene3-java
cpe:/o:debian:debian_linux:10.x
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies