Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <1385507213.8432.15.camel@banzai>
Date: Wed, 27 Nov 2013 00:06:53 +0100
From: Nicolas Grégoire <nicolas.gregoire@...rri.fr>
To: oss-security@...ts.openwall.com
Subject: CVE request: Apache Solr 4.6.0

Hello,

Apache Solr 4.6.0 was released a few days ago. This version includes a
fix for bug SOLR-4882 (directory traversal when accessing XSLT
stylesheets and Velocity templates):
http://lucene.apache.org/solr/4_6_0/changes/Changes.html#v4.6.0.security
https://issues.apache.org/jira/browse/SOLR-4882

If the user can store his own files on the server, this vulnerability
could be abused to gain remote code execution.

Regards,
Nicolas Grégoire



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.