Executive Summary

Informations
Name CVE-2025-24814 First vendor Publication 2025-01-27
Vendor Cve Last vendor Modification 2025-06-25

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.4 Temporal Score 5.5
Exploitabality Sub Score 2.1
 
Attack Vector Network Attack Complexity Low
Privileges Required Low User Interaction Required
Scope Unchanged Confidentiality Impact Low
Integrity Impact Low Availability Impact Low
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Core creation allows users to replace "trusted" configset files with arbitrary configuration

Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization are vulnerable to a sort of privilege escalation wherein individual "trusted" configset files can be ignored in favor of potentially-untrusted replacements available elsewhere on the filesystem. These replacement config files are treated as "trusted" and can use "" tags to add to Solr's classpath, which an attacker might use to load malicious code as a searchComponent or other plugin.

This issue affects all Apache Solr versions up through Solr 9.7. Users can protect against the vulnerability by enabling authentication and authorization on their Solr clusters or switching to SolrCloud (and away from "FileSystemConfigSetService"). Users are also recommended to upgrade to Solr 9.8.0, which mitigates this issue by disabling use of "" tags by default.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24814

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 56

Sources (Detail)

http://www.openwall.com/lists/oss-security/2025/01/26/1
https://lists.apache.org/thread/gl291pn8x9f9n52ys5l0pc0b6qtf0qw1
https://security.netapp.com/advisory/ntap-20250214-0002/
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2025-06-25 21:20:47
  • Multiple Updates
2025-06-24 21:20:48
  • Multiple Updates
2025-02-15 09:20:35
  • Multiple Updates
2025-02-06 21:20:34
  • Multiple Updates
2025-01-27 13:20:33
  • First insertion