CVE-2019-12401

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-09-10 15:15

Updated : 2023-11-07 03:03


NVD link : CVE-2019-12401

Mitre link : CVE-2019-12401

CVE.ORG link : CVE-2019-12401


JSON object : View

Products Affected

apache

  • solr
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')