CVE-2019-12401

HIGH

Solr <4.10.4 - DoS

Title source: llm

Description

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

Exploits (1)

nomisec SUSPICIOUS
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2019-12401

Scores

CVSS v3 7.5
EPSS 0.3277
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-776
Status published
Products (2)
apache/solr 1.3.0 - 1.4.1
org.apache.solr/solr-core 0 - 5.0.0Maven
Published Sep 10, 2019
Tracked Since Feb 18, 2026