CVE-2013-6397
Published Dec 7, 2013
Last updated a year ago
Overview
- Description
- Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "037FEB16-6126-4951-B8FD-D56CF268CFBF", "versionEndIncluding": "4.5.1" }, { "criteria": "cpe:2.3:a:apache:solr:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06216B21-FC73-480F-90A2-B0D358FAEE11" }, { "criteria": "cpe:2.3:a:apache:solr:4.0.0:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49D9F075-B18A-4634-8AA1-DE1399548838" }, { "criteria": "cpe:2.3:a:apache:solr:4.0.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0CFB9E78-22B2-4683-BD17-1600A3057FF3" }, { "criteria": "cpe:2.3:a:apache:solr:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AF6C877-D6B6-40A8-9A73-0B327898F8E2" }, { "criteria": "cpe:2.3:a:apache:solr:4.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C085709-D90B-44AC-89E1-3D2779956B89" }, { "criteria": "cpe:2.3:a:apache:solr:4.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F36E7460-4056-4608-96BA-622FF2770DBB" }, { "criteria": "cpe:2.3:a:apache:solr:4.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8444B03D-D600-4C30-85F3-E2497270768A" }, { "criteria": "cpe:2.3:a:apache:solr:4.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA07EC5A-CE8F-403E-91C1-8E7D79CD573F" }, { "criteria": "cpe:2.3:a:apache:solr:4.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D09D035F-9B45-4758-ADCD-D6BF8B95AACB" }, { "criteria": "cpe:2.3:a:apache:solr:4.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F01B2DB5-EFEB-472C-B7F7-0B7B5229D488" } ], "operator": "OR" } ] } ]