Total vulnerabilities in the database
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.
Software | From | Fixed in |
---|---|---|
apache / solr | 1.3.0 | 7.6.0.x |
![]() |
1.30 | 7.7.0 |