CVE Published: 08/03/2019 |
CVE Updated: 16/09/2024 |
CVE Year: 2017 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Solr Status : PUBLISHED
CVE-2017-3164 Description
Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist mechanism, a remote attacker with access to the server could make Solr perform an HTTP GET request to any reachable URL.